This is a healthy, mature package to depend on: it has been maintained for roughly 10 years, has 31 releases including 7 in the last 12 months, a stable non-prerelease version, an active and non-archived organization-owned repository, recent commits from two active contributors, repository tests and changelog coverage, and no install-time lifecycle scripts. The main reservations are the absence of a security policy and dedicated security scanning, plus an undeclared top-level GitHub Actions token-permissions policy; these are transparency and CI-hardening gaps rather than evidence of abandonment. Registry maintainer access is limited to two accounts, but the organization-backed repository and active contributor activity provide meaningful continuity.
88%
Total Score
100
100
94
80
Composer build tooling is present, but no security-scanning tool was detected; this is a modest CI transparency gap for a package with external dependencies.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The only workflow lacks top-level token permissions, and no read-only permissions are declared; this weakens CI least-privilege documentation even though no write permissions were explicitly observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0|^3.0 | — | — |
illuminate/http Version ^12.0|^13.13 | — | — |
illuminate/support Version ^12.0|^13.13 | — | — |
minishlink/web-push Version ^11.0 | — | — |
illuminate/notifications Version ^12.0|^13.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.