Healthy and suitable to depend on, with normal 0.x API-change risk. Recent releases, active multi-contributor development, extensive tests, and a matching repository outweigh the lack of a security policy and explicit workflow token permissions.
84%
Total Score
100
100
89
80
Composer-based build tooling is present, but no security scanning tools were detected. The missing scanner is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations and contact information unspecified.
All three workflows lack top-level token-permission declarations. No workflow requests top-level write access, but explicit least-privilege declarations would provide clearer CI hardening.
Version v0.10.0 is not a prerelease, but the 0.x major version signals that breaking API changes remain possible compared with a stable 1.x release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.