Usable with caveats: the release is well-documented, licensed, actively built, and backed by a matching organization repository. It is only 39 days old, has one release and one active contributor, with an install script and a write-enabled automation workflow adding operational risk.
68%
Total Score
83
100
94
63
One of three workflows uses pull_request_target, a sensitive automation trigger. No untrusted checkout or script injection was detected, so this is a workflow-risk caution rather than a severe finding.
The package runs a post-autoload-dump install-time script. This is an additional execution point during installation and deserves review, although the signal does not show that the script is malicious or unusually broad.
This is a very new package, only 39 days old, with one release and no established release cadence. That leaves limited evidence of long-term maintenance and compatibility stability.
All 16 recent commits came from one contributor, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is evidenced here.
All workflows declare permissions, and two are read-only; one Dependabot auto-merge workflow has top-level write permissions, increasing the impact of an automation compromise.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0||^13.0 | — | — |
illuminate/events Version ^12.0||^13.0 | — | — |
illuminate/console Version ^12.0||^13.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.