The README is clear, the version is stable, and the repository has Composer build tooling with security scanning. Its single registry maintainer and absent security policy leave limited operational depth.
55%
Total Score
50
100
94
75
The repository recorded zero commits and zero active maintainers in the last three months, with its last push about four months ago. For a package this young, that is a meaningful sign of stalled maintenance.
Only one account has registry publish access. Because the repository is organization-owned, this is partly expected publishing hygiene, but it still leaves a narrow observed release path.
The package is only about 144 days old and published seven releases, with most releases arriving within roughly four days. This shows an initial burst but not yet a mature maintenance record.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in an integration that processes webhook and access-token data.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.0|^8.0|^9.0 | — | — |
illuminate/routing Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.