The package has clear documentation, repository tests, regular releases, and a matching source project. Its limited ownership and missing security safeguards leave less backup if maintenance slows.
68%
Total Score
50
94
67
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of continuing maintenance despite the recent release history.
Composer is used for builds, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
The one workflow was fully analyzed and has no dangerous triggers, untrusted checkouts, script injections, or write-wide permissions. However, both of its two action references are unpinned, weakening build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.4|^8.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/filesystem Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.