Documentation is strong, and the release notes describe 255 tests with full coverage. The single-contributor workflow and unpinned CI actions make long-term upkeep less certain; pin this version if adopting.
66%
Total Score
75
93
67
The package is only 62 days old and has two releases, both published on the same day, so its maintenance record is still limited.
One contributor made 100% of the three recent commits. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository had three commits in the last three months, showing some recent activity, but only one active maintainer limits evidence of sustained maintenance capacity.
The repository has no security policy. This is a transparency gap for a package handling electronic invoicing and certificates, though it is not evidence of a security incident.
The workflow audit completed cleanly, uses read-only permissions, and found no dangerous triggers or audit findings. However, both of its two action references are unpinned, leaving a modest CI supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^12.0 || ^13.0 | — | — |
illuminate/log Version ^12.0 || ^13.0 | — | — |
illuminate/http Version ^12.0 || ^13.0 | — | — |
illuminate/queue Version ^12.0 || ^13.0 | — | — |
illuminate/console Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.