The README, changelog, MIT license, and package layout give consumers useful documentation. It has no install-time scripts, but its workflow actions are all unpinned, creating a smaller reproducibility concern.
52%
Total Score
50
92
67
Only one registry publishing maintainer is listed, leaving the project dependent on a thin individual maintainer base; the linked repository is also owned by a user account rather than an organization.
The latest release was published in February 2023, with no releases in the following three years and seven months; this is a substantial maintenance concern for a Laravel integration.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less severe for this small package than the lack of recent maintenance.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all five referenced actions are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^5.0|^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.