The package is licensed, documented, tested in its repository, and has a stable release history. Maintenance has been quiet for six months, and both workflow actions are unpinned; there is also no published security policy.
68%
Total Score
50
100
67
The repository recorded zero commits and zero active maintainers in the last three months, and its latest push was about six months ago; this is a meaningful maintenance concern despite the recent release history.
The repository has no SECURITY.md policy. This is a transparency and reporting gap, although it is less serious than evidence of an active vulnerability.
The single workflow was fully analyzed with no trigger or high-confidence audit findings, but both of its two action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.34 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
friendsofphp/php-cs-fixer Version ^3.47 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.