Healthy and reasonable to depend on. It has recent releases, active repository contributors, tests, release notes, and clear project backing; the main caveats are a single registry publisher and workflows without explicit top-level token permissions.
82%
Total Score
80
100
100
80
A post-autoload-dump install-time script is present, creating some supply-chain and installation complexity; no provided workflow signal shows that it is dangerous.
Only one account has registry publishing access, which is a mild operational concentration risk; the organization-backed repository and two active repository contributors provide some compensation.
There are two open pull requests and no issues or merged pull requests in the last month, which is a small activity concern, though recent commits and the current release provide stronger maintenance evidence.
Neither analyzed workflow declares top-level token permissions, leaving permissions less explicit than recommended; neither workflow requests top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.