A substantial README, tests, release notes, and organization ownership make the package easier to evaluate and support. CI uses Dependabot, but workflow pinning and security documentation are weaker than its otherwise solid presentation.
68%
Total Score
100
100
94
67
The package has five releases, all within roughly two days, and is only about three months old. This shows initial activity but provides little evidence of sustained maintenance yet.
The repository has no security policy. That weakens vulnerability-reporting transparency for a package that captures application telemetry and exposes monitoring APIs.
All six referenced actions are unpinned, and one release workflow grants top-level write permissions. The only audit finding is low-confidence cache poisoning, which is hygiene rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/mail Version ^10.0|^11.0|^12.0|^13.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
illuminate/queue Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.