The project has recent releases, tests, release notes, and a matching repository. Maintenance is concentrated in one contributor, and the workflow uses two unpinned actions.
42%
Total Score
50
86
50
Packagist marks the entire package as abandoned, with no distinct replacement package provided. This is a direct adoption and future-maintenance warning despite the recent release activity.
Only one registry account has publish access. The matching user-owned repository provides some context, but there is still no observed publishing redundancy.
All 3-month commit activity comes from one contributor, with one contributor making 100% of commits. That creates a meaningful continuity risk for a user-owned project.
The repository has no security policy. For a small package this is a transparency gap rather than evidence of unsafe code, but it reduces clarity about vulnerability reporting and response.
The single workflow is fully analyzed, uses read-only permissions, and has no detected dangerous sinks or audit findings. However, both action references are unpinned, leaving a modest build-reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^5.1 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^5.1 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.