The repository includes tests, a security policy, and detailed release notes. Issue closure and commit activity are strong, though this remains a young project with limited contributor depth.
70%
Total Score
75
100
100
88
The repository is owned by a personal GitHub account rather than an organization, so the concentrated contributor activity is not offset by visible organizational backing.
Two contributors were active in the last three months, but one contributed 109 of 110 commits, leaving maintenance highly concentrated.
All six workflows were analyzed without failed files or detected sinks, but all 21 action references are unpinned and four workflows grant top-level write permissions. These are workflow hygiene and permission-width concerns, not evidence of an active exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/queue Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/database Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
laravel/serializable-closure Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.