Clear licensing, useful documentation, and organization backing support dependable adoption. The workflow is mostly clean, though its sole action is unpinned and the repository lacks a security policy.
84%
Total Score
83
100
94
50
No commits or active maintainers were recorded in the last three months, which is a maintenance warning, although the package's frequent recent releases and current repository push provide meaningful counterevidence.
Composer is used for the build, but no security scanning tool was detected; this is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for a widely used database component.
The only workflow was fully analyzed with no audit findings or untrusted checkout/script-injection sinks. Its one action is unpinned, which is a limited reproducibility and supply-chain hygiene concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-24940 illuminate/database is vulnerable to Security Vulnerability in versions 5.5.0 - 5.5.44, 6.0.0 - 6.18.34 and 7.0.0 - 7.23.2. | 5.5.0 - 5.5.446.0.0 - 6.18.347.0.0 - 7.23.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
brick/math Version ^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19 || ^0.20 || ^1.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/container Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
illuminate/macroable Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.