The package has a matching repository, tests, release notes, and a small dependency surface. Its workflow leaves all three actions unpinned, and no security policy is published.
78%
Total Score
83
100
94
83
No commits and no active maintainers were recorded in the three months before assessment. This is a maintenance concern, although the recent release and longer release history provide some compensation.
Composer build tooling is present. No security scanning tools are configured, which is a minor transparency gap but not severe for this small package.
The repository has no published security policy, leaving vulnerability reporting and response expectations unspecified.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all three action references are unpinned, creating a modest reproducibility and dependency-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version ~9.0|~10.0|~11.0|~12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.