The package has a clear README, MIT licensing, and no install-time scripts. Its small release history and unpinned CI actions leave modest maturity and workflow-hygiene gaps.
78%
Total Score
100
86
75
The package is only 91 days old with four releases, so its long-term maintenance record is still limited. Releases have arrived regularly, with a median interval of about 9 hours, which provides some evidence of active development.
The repository has no published security policy, leaving reporting and response expectations unclear. This is a transparency gap, but the small, actively maintained project provides some compensating context.
Version v0.4.0 is not on a stable major release, so compatibility may still change as the package matures. It is not marked as a prerelease, which partly offsets that concern.
The sole workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. Both action references are unpinned, creating a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/cache Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
gmostafa/php-graphql-client Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.