Repository tests, release notes, and organization backing provide useful maintenance evidence. The small package footprint limits popularity evidence, while the workflow setup deserves extra care before adoption.
68%
Total Score
75
100
94
75
No commits or active maintainers were observed in the last three months. The recent release and push partly offset this, but the quiet interval still raises a maintenance concern.
Composer build tooling is present, but no security-scanning tools were detected. For this small package that is a hygiene gap rather than evidence of abandonment.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself indicate that the package is unsafe to depend on.
All 11 analyzed action references are unpinned, which makes workflow inputs less reproducible. Two workflows grant top-level write permissions, a mild concern; no dangerous triggers, untrusted checkouts, script injections, or audit findings were reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.