The README, tests, matching repository, and MIT license provide a credible starting point. The release workflow uses unpinned actions, including archived ones, and the project has no security policy. Pin this exact version only if you accept an early API.
58%
Total Score
50
71
67
The artifact and repository contain a license file, and the declared MIT license is accompanied by detected MIT-0 text; licensing is present, though the declaration mismatch warrants care.
This is the package's only release, published about 10 months ago, so there is little evidence of an established maintenance cadence.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has gone quiet after its initial release.
The repository uses Composer build tooling but has no security scanning tools, leaving a modest transparency and maintenance gap.
No security policy is present, so the process for reporting and handling vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ^10.0|^11.0 | — | — |
illuminate/support Version ^10.0|^11.0 | — | — |
illuminate/database Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.