The package is licensed, stable, and backed by an organization with a long release history. Missing security scanning and an unpinned workflow reference leave modest maintenance and build-hygiene concerns.
72%
Total Score
75
100
88
67
The artifact has no README, tests, or changelog, and the repository also reports none. The missing consumer documentation is a modest transparency gap, while tests and changelogs are not expected in every published artifact.
The repository records zero commits and zero active maintainers over the last three months, which weakens evidence of ongoing development despite the recent release and push timestamps.
Composer is used for builds, but no security-scanning tool was detected. This is a modest project-hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, reducing transparency around vulnerability reporting and response expectations.
The sole workflow is fully analyzed and has no reported audit findings; its pull_request_target trigger has no untrusted checkout or script-injection sink. However, its one action reference is unpinned, leaving a minor supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^13.0 | — | — |
illuminate/mail Version ^13.0 | — | — |
illuminate/queue Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/container Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.