It has a clear README, MIT licensing, repository tests, and no install-time scripts. The small dependency set and matching repository help, but security scanning and a security policy are absent.
66%
Total Score
50
100
94
75
The repository recorded zero commits and zero active maintainers during the last three months. The recent release and push provide some counter-evidence, but current development activity remains thin.
Composer build tooling is present, but no security-scanning tools were detected, leaving automated vulnerability coverage unclear.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
Both workflows were analyzed successfully with no injection sinks or high-severity findings, but all six action references are unpinned. This weakens build reproducibility and makes action changes less controlled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
illuminate/support Version ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.