Clear documentation, tests, and release notes make integration easier. The repository has had no commits for four months, and its workflows use an unpinned container image; there is also no security policy.
60%
Total Score
75
100
88
67
The package is mature at about 3 years old, but it has only one release in the last 12 months and the latest release was about 4 months ago, indicating a slower cadence.
There were no commits and no active maintainers in the last 3 months; combined with the four-month-old latest push, this is evidence of slowed maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and hygiene gap.
The linked repository has no security policy, which makes vulnerability-reporting expectations less clear for a package handling application-key rotation.
Both workflows were fully analyzed with no untrusted checkout or script-injection findings, but all 9 action references are unpinned and a high-confidence finding identified an unpinned container image. This weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.