The package has clear documentation, release notes, tests in the repository, and a permissive MIT license. Its young project has only one active contributor and one commit in the past three months, with no security policy and unpinned workflow actions.
68%
Total Score
50
94
50
One contributor made 100% of the one recent commit, leaving maintenance fully concentrated in a single person with no demonstrated handoff capacity.
Only one commit was recorded in the past three months, indicating limited recent maintenance activity for a package with a young release history.
The repository uses Composer build tooling, but no security-scanning tools were detected, leaving a modest gap in automated security hygiene.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The workflow audit completed successfully with no untrusted checkout or script-injection findings, but both analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
validators/sa Version ^1.0 | — | — |
illuminate/bus Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
symfony/process Version ^6.4|^7.0|^8.0 | — | — |
illuminate/queue Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.