The MIT license, repository tests, and matching source make the package transparent. Its pre-1.0 version and lack of a security policy leave less maturity and assurance than an established dependency.
67%
Total Score
67
50
88
75
The package declares nine runtime dependencies, including framework and Graph integrations. This is a meaningful dependency surface but not excessive evidence of poor health on its own.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This supports ownership consistency while offering limited handoff capacity.
One contributor made all 8 commits in the last 3 months, leaving maintenance highly concentrated and increasing continuity risk if that contributor becomes unavailable.
Composer build tooling is present, but no security scanning tools were detected. The absence lowers assurance modestly without proving a maintenance problem.
The repository has no security policy. For a package managing Microsoft Graph resources and application secrets, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/volt Version ^1.6.7 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
hwkdo/ms-graph-laravel Version dev-main || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.