It has a clear MIT license, tests, and release notes for this version. The small public footprint and absent security policy leave less independent assurance; verify the repository before rollout.
70%
Total Score
88
83
50
The repository owner is an individual rather than an organization, so the nearly even two-contributor activity helps but does not provide organizational handoff assurance.
The repository name does not match the package name and its README does not mention the package, so the link may not clearly establish that this source belongs to the published package.
The repository has 2 stars, 0 forks, and 1 watcher; this is limited independent adoption evidence, but popularity is supporting evidence and does not outweigh the strong recent activity.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest assurance gap for a package handling API credentials and webhooks.
The repository has no security policy, reducing transparency about vulnerability reporting and response for an integration that handles messaging and access tokens.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/queue Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.