Usable with caveats: the package is licensed, backed by an organization, tested in its repository, and not deprecated. However, it has only one release and no commits or active maintainers recorded in the last three months, with some GitHub workflow permission concerns.
62%
Total Score
75
88
50
One of three workflows uses pull_request_target, which requires elevated trust because it can run with repository privileges, although no untrusted checkout or script-injection pattern was detected.
This package is 178 days old but has only one release, so there is little release history to demonstrate sustained maintenance or compatibility handling.
The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful maintenance concern for a package with only one release.
The repository has zero stars and one fork, offering little community validation; this is supporting evidence only and is partly expected for a newly published package.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
facade/ignition-contracts Version ^1.0.2|^2.0 | — | — |
spatie/php-attribute-reader Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.