The package includes tests, a changelog, documentation, and an MIT license. Unpinned workflow actions and the lack of a security policy add smaller maintenance and supply-chain concerns.
43%
Total Score
71
75
Only one release exists, published over three years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a Laravel library.
The repository has only 1 star, 0 forks, and 0 watchers. Popularity is not decisive by itself, but this offers little supporting evidence of ongoing use or review.
Composer is used for the build, but no security-scanning tooling is present. This is a modest transparency and maintenance gap rather than a severe risk.
No security policy is present in the repository. For a package used in applications, this makes vulnerability reporting and response expectations less clear.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 3 action references are unpinned. That leaves avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^10.0 | — | — |
illuminate/config Version ^10.0 | — | — |
illuminate/console Version ^10.0 | — | — |
illuminate/support Version ^10.0 | — | — |
illuminate/database Version ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.