The package includes tests, a clear README, and only two runtime dependencies. Its workflow uses three unpinned actions, while the repository has no security scanning or security policy, limiting build assurance and maintenance transparency.
60%
Total Score
50
100
86
67
The package has four releases but none in the last 12 months; the latest release was in August 2023, indicating materially slowed maintenance for a dependency assessed in 2026.
There were no commits from active maintainers in the last 3 months, consistent with an inactive project and increasing abandonment risk.
Composer is used for builds, but no security scanning tool is configured; this is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented and reducing maintenance transparency.
The single workflow was fully analyzed, uses read-only permissions, and has no reported audit findings, but all three action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/config Version 5.*|6.*|7.*|8.*|9.*|10.*|11.*|12.*|13.*|14.*|15.*|16.*|17.*|18.*|19.*|20.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.