The package has a clear license, repository tests, a changelog, and a security policy. Install-time automation and absent security scanning leave additional operational risk.
61%
Total Score
83
88
67
The package runs a post-autoload-dump install-time script, which adds execution and review risk beyond a package with no lifecycle automation.
The repository is owned by an individual rather than an organization, so continuity depends more directly on the maintainers; the recent multi-contributor activity partly offsets that concern.
This is the first release, published one day ago, so there is no meaningful history showing sustained maintenance or compatibility over time.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest gap in ongoing project hygiene.
The workflow audit completed fully and found read-only permissions with all action references pinned, but it reported six high-confidence unpinned container-image findings in tests.yml. These are CI reproducibility and supply-chain hygiene concerns, not evidence that the release is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/uri Version ^7.5.1 | — | — |
nesbot/carbon Version ^2.67|^3.0 | — | — |
illuminate/auth Version ^11.0.8|^12.0|^13.0 | — | — |
illuminate/http Version ^11.0.8|^12.0|^13.0 | — | — |
illuminate/view Version ^11.0.8|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.