Clear documentation, repository tests, MIT licensing, and release notes make integration and ownership transparent. The one-person publishing base, absent security policy, and unpinned workflow actions warrant pinning this version while maintenance catches up.
70%
Total Score
50
94
50
The repository recorded 0 commits and 0 active maintainers in the last three months. This is partly offset by the recent 4.8.0 release, but it still leaves current maintenance momentum uncertain.
The project uses Composer, but no security-scanning tools were detected. That is a modest supply-chain transparency gap rather than evidence of unsafe code.
No repository security policy was found, leaving vulnerability-reporting expectations unclear for consumers of this library.
All 5 workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, or audit findings. However, all 11 action references are unpinned, creating a reproducibility and action-supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brick/geo Version 0.13.* | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.