The source repository includes a substantial test suite, release notes, and a clear MIT license. It has no security policy or scanning, leaving important project hygiene less transparent.
73%
Total Score
83
100
88
67
This is the package's first release and it was published today, so there is no release track record yet. Its newness explains the lack of history but still leaves maintenance consistency unproven.
There were no commits in the last three months, but the repository is brand new and was pushed shortly before this release. This limits evidence of sustained maintenance rather than showing a demonstrated collapse.
Composer build tooling is present, but no security-scanning tool was detected. That is a transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving reporting and response expectations undocumented. This is a moderate transparency gap for a package that handles analytics credentials.
All three workflows were analyzed without audit findings or untrusted-code sinks, but all five action references are unpinned and one workflow grants top-level write permissions. These are workflow hygiene concerns, with the write scope being mild on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
illuminate/queue Version ^11.0|^12.0|^13.0 | — | — |
mirafive/sdk-php Version ^1.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.