The project has a long release history, stable versions, tests, release notes, and a security policy. Its single-maintainer base, no commits in three months, and entirely unpinned workflow actions leave meaningful maintenance and build-integrity caveats.
68%
Total Score
63
100
94
83
Only one registry account has publish access, which creates some publishing continuity risk; the long release history and linked maintained project provide partial compensation.
The package is linked to a personal-user-owned repository rather than an organization, so the one-person publishing and maintenance model carries more continuity risk.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign of currently inactive development despite a recent release and push.
Composer is used for builds, but no security scanning tools were detected, leaving a modest transparency and maintenance-hygiene gap.
Both workflows were analyzed cleanly with no reported audit findings or untrusted-code sinks, but all 8 action references are unpinned, so workflow dependencies can change unexpectedly.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^10.44 || ^11.0 || ^12.0 || ^13.0 | — | — |
league/commonmark Version ^2.8.2 | — | — |
illuminate/support Version ^10.44 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^10.44 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/filesystem Version ^10.44 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.