Usable with caveats: it has clear documentation, tests, licensing, and recent activity from an organization-backed repository. However, it is only 53 days old, has just three releases, and lacks a security policy and automated security scanning.
72%
Total Score
83
88
75
The package is only 53 days old and all three releases occurred within a very short period, leaving limited evidence of long-term maintenance and release stability.
Commit activity is evenly split between two contributors, reducing single-person concentration; the small contributor base still limits resilience if either stops contributing.
Composer build tooling is present, but no security scanning tools are configured, leaving a transparency and maintenance gap for a package that handles signed license tokens.
The repository has no security policy, so users are given no documented process for reporting or handling vulnerabilities in a package that exposes authentication-related licensing features.
The repository workflow lacks top-level GitHub Actions permissions, so its token scope is not explicitly constrained; this is a workflow-hardening gap, though no write permissions were observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/console Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/routing Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.