The repository has clear documentation, tests, release notes, and broad automated security tooling. Organization backing and active pull requests help, but this is too new to demonstrate sustained maintenance, and workflow references need tighter pinning.
63%
Total Score
83
94
75
The package runs post-install and post-update Composer scripts. These add installation-time execution surface, though the signal does not show that the scripts are harmful or unusually broad.
The package is only 0 days old with two releases published within roughly one hour, so there is not yet enough history to establish dependable maintenance or release continuity.
No commits or active maintainers were recorded in the last three months. Because the project is newly published, this is primarily a lack of established maintenance evidence rather than proof of abandonment.
All 11 workflows were analyzed with no reported audit findings or untrusted checkout/script-injection sinks. However, 40 of 47 action references are unpinned, and four workflows grant top-level write permissions, creating avoidable workflow-supply-chain and token-scope exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/mail Version ^12.0|^13.0 | — | — |
jooservices/dto Version ^3.2 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
jooservices/client Version ^4.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.