The package includes tests, a substantial README, and a matching MIT license. Its organization-backed repository is active in this newly published snapshot, but workflow actions are unpinned and the project has little demonstrated history.
68%
Total Score
75
100
86
75
All four releases appeared within about 18 minutes, and the package is less than a day old. This shows active initial publishing but provides almost no long-term maintenance record.
No commits or active maintainers were recorded in the last three months. Because the repository is less than a day old, this is mainly limited history rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tools were detected. The missing scanner is a modest repository-hygiene gap, not a standalone dependency risk.
The repository has no security policy. That reduces disclosure transparency for a library handling account and fraud-related data, though it does not show an operational failure.
The single workflow was fully analyzed with no audit findings or untrusted triggers, and it has no top-level write permissions. However, both of its action references are unpinned, leaving the build exposed to action-reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
illuminate/validation Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.