The package includes a license, README, release notes, and repository tests. Its workflows use unpinned actions and the repository has no security policy, adding maintenance risk.
42%
Total Score
0
70
50
The package has had no registry release in nearly four years, despite only five releases overall. This is strong evidence of abandonment for a dependency that may need compatibility updates.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long absence of releases. No recent development activity compensates for this gap.
The repository has only 3 stars and 1 fork, providing little community evidence or backup maintenance capacity. Popularity is supporting evidence, so this reinforces rather than determines the abandonment concern.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a hygiene and maintenance concern, not evidence that the package is unsafe by itself.
All three workflows were analyzed without high-confidence findings or dangerous triggers, but all eight action references are unpinned. That leaves avoidable workflow supply-chain exposure, though no write-wide token or untrusted checkout was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version * | — | — |
illuminate/cache Version ^5.0|^6.0|^7.0|^8.0|^9.0 | — | — |
illuminate/support Version ^5.0|^6.0|^7.0|^8.0|^9.0 | — | — |
willdurand/geocoder Version ^4.0 | — | — |
illuminate/contracts Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.