Usable with caveats: this is a mature, licensed package from an organization-backed project with a long release history, but it has had no commits or active maintainers in the last three months. The repository also lacks security scanning and contains a pull-request-target workflow without explicit token permissions.
68%
Total Score
75
100
88
50
One workflow uses pull_request_target, which can require careful handling of untrusted pull requests; no untrusted checkout or script injection was detected, so this is a contained workflow risk rather than a severe finding.
The published artifact has no README, tests, or changelog, but the package is a small component and published packages commonly omit source tests and changelogs; the missing README is still a minor consumer-documentation gap.
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful maintenance concern that is partly offset by the recent release history and organization backing.
Composer build tooling is present, but no security scanning tools were detected, leaving a repository hygiene and review gap.
The repository has no published security policy, reducing transparency about vulnerability reporting and response practices.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^13.0 | — | — |
illuminate/collections Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.