Documentation, tests, release notes, licensing, and a security policy make the project transparent to adopt. The workflow uses two unpinned actions and the repository reports no security scanning, adding modest process risk.
68%
Total Score
50
94
100
The repository recorded zero commits and zero active maintainers in the past three months. Because this is a young package, that lull is a meaningful maintenance concern despite the recent release.
Composer build tooling is present, but no security scanning tools were detected, leaving a gap in repository security process.
The single workflow uses read-only permissions and has no untrusted checkouts, injection findings, or audit failures. However, both referenced actions are unpinned, which weakens build reproducibility and action supply-chain protection.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 || ^13.0 | — | — |
illuminate/console Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/database Version ^12.0 || ^13.0 | — | — |
illuminate/filesystem Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.