The package is clearly identified, licensed, tested, and documented, with a release for Laravel 13. Maintenance has been quiet for about six months, and all five workflow actions are unpinned; the missing security policy adds a smaller transparency concern.
68%
Total Score
50
90
50
The package has existed since September 2020 with 31 releases, but only one release in the last 12 months and the latest was about six months ago. This suggests slower maintenance, though the recent release provides evidence the project is not abandoned.
No commits or active maintainers were recorded in the last three months. The March 2026 release partly offsets this, but the recent inactivity still raises maintenance risk.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is not evidence that the package is unsafe.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all five action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ^11.0 | ^12.0 | ^13.0 | — | — |
illuminate/database Version ^11.0 | ^12.0 | ^13.0 | — | — |
illuminate/contracts Version ^11.0 | ^12.0 | ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.