The package has focused dependencies, repository tests, a matching source repository, and a security policy. Maintenance has effectively stopped since November 2023, and all 11 workflow actions are unpinned, so pinning this release requires accepting stale-project and build-integrity concerns.
55%
Total Score
50
100
79
50
The package has had no release in nearly three years: all 16 releases occurred by November 2023, with none in the last 12 months. This is substantial abandonment evidence despite the package having an established release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no recent activity showing ongoing maintenance.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a minor transparency gap, not evidence that the package is unsafe by itself.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 11 action references are unpinned. That leaves build automation exposed to changing action contents and is a meaningful hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^5.5 || ^6.0 || ^7.0 || ^8.0|| ^9.0 || ^10.0 | — | — |
illuminate/events Version ^5.5 || ^6.0 || ^7.0 || ^8.0|| ^9.0 || ^10.0 | — | — |
illuminate/support Version ^5.5 || ^6.0 || ^7.0 || ^8.0|| ^9.0 || ^10.0 | — | — |
illuminate/container Version ^5.5 || ^6.0 || ^7.0 || ^8.0 || ^9.0 || ^10.0 | — | — |
illuminate/contracts Version ^5.5 || ^6.0 || ^7.0 || ^8.0|| ^9.0 || ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.