The MIT license and focused five-package runtime dependency set make adoption straightforward. The repository shows no commits or active maintainers in the last three months, and its only workflow uses an unpinned action, leaving maintenance and build-reproducibility concerns.
70%
Total Score
83
100
94
50
The repository recorded zero commits and zero active maintainers over the last three months. This conflicts with the package's frequent release history and lowers confidence in current source maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy. This is a transparency gap for vulnerability reporting, though it is not by itself evidence of unsafe code.
The single workflow uses a pull_request_target trigger without an untrusted checkout or script injection, so the trigger is ordinary. However, its one action reference is unpinned, which weakens build reproducibility; the audit itself completed fully with no findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
illuminate/macroable Version ^13.0 | — | — |
illuminate/collections Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.