Healthy and reasonable to depend on. It has a long release history, current stable releases, strong project backing, tests, release notes, and security tooling; recent repository activity is light and concentrated in one contributor, so maintenance depth is the main caveat.
82%
Total Score
67
100
100
80
One pull_request_target workflow is present, which warrants some workflow review, but there are no untrusted checkouts or script-injection findings among the analyzed workflows.
All recent commits came from one contributor, leaving a concentrated maintenance base. Organization backing reduces handoff risk somewhat, but no second recently active contributor is shown.
Only one commit was recorded in the last three months, with one active maintainer. This is light recent maintenance for a still-released package and lowers confidence in the depth of ongoing support.
All analyzed workflows declare top-level permissions, while two are read-only. Four workflows request write permissions, which is broader than ideal, but the explicit declarations reduce ambiguity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.0|^8.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/filesystem Version ^11.0|^12.0|^13.0 | — | — |
illuminate/validation Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.