Usable with caveats: the release is licensed, documented, tested, and backed by an active organization-owned repository. However, the repository had no commits or active maintainers in the last three months, and it lacks a security policy and explicit workflow permissions.
70%
Total Score
75
89
80
The repository recorded zero commits and zero active maintainers in the last three months. Although a recent release exists, the absence of recent source activity creates a meaningful maintenance concern.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption signal to offset the thin recent activity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
No repository security policy was found, reducing transparency about how vulnerabilities should be reported and handled.
The single GitHub Actions workflow has no top-level token permissions declaration. No write permissions were detected, but explicit least-privilege settings would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 || ^7.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/notifications Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.