Clear documentation, tests, and licensing make the package easy to evaluate. Maintenance has gone quiet, with no commits or active maintainers in three months. The workflow is clean but uses two unpinned actions, and no security policy or scanning is provided.
58%
Total Score
50
100
88
67
Three releases arrived within roughly two days, but the latest release is about five months old. The short history provides limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. For a package released only about five months ago, this is a meaningful maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence of abandonment on its own.
The repository has no security policy. This weakens the project's disclosure and response transparency, though it does not outweigh the available tests and documentation by itself.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving avoidable maintenance and integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/horizon Version ^5.0 | — | — |
illuminate/cache Version ^11.0|^12.0|^13.0 | — | — |
illuminate/config Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.