The repository includes tests, a changelog, a license, and Psalm security scanning, which provide useful project discipline. All ten GitHub Actions references are unpinned and no security policy is published, leaving build-integrity and transparency gaps.
58%
Total Score
50
94
75
The repository is owned by an individual account rather than an organization, so the single-contributor maintenance concentration is not visibly offset by broader project backing.
This is a 96-day-old package with only one release, so there is little evidence of sustained maintenance or release maturity.
One contributor made 100% of recent commits, creating a concentrated maintenance dependency with no demonstrated handoff capacity.
Only one commit was recorded in the last three months from one active maintainer, so ongoing maintenance is not yet demonstrated.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.