MIT licensing and organization backing make the package straightforward to evaluate. However, no commits were recorded in the past three months despite frequent releases, and the workflow uses an unpinned action without security scanning or a security policy.
70%
Total Score
75
93
67
No commits and no active maintainers were recorded in the past three months. The frequent registry releases partly offset this concern, but the observed repository activity still weakens maintenance confidence.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The linked repository has no security policy, which makes vulnerability reporting expectations less clear for a package intended for application dependencies.
The single workflow was fully analyzed with no audit findings or untrusted checkout and script-injection sinks. However, its one action is unpinned, so workflow supply-chain hygiene is weaker than it could be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
illuminate/bus Version ^13.0 | — | — |
illuminate/queue Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/container Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.