It has clear licensing, release notes, repository tests, and a recent Laravel 13 release. The repository is active enough to publish releases and has security tooling, but recent commit activity is absent and its automation needs tightening.
68%
Total Score
75
100
75
The repository recorded zero commits and zero active maintainers during the last three months, weakening confidence that defects or compatibility changes will be addressed promptly.
All three analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene and automation concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/database Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
illuminate/filesystem Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.