The package includes tests, a substantial README, and release notes for this version. Its organization-backed repository is active, but the declared MIT license conflicts with the detected Apache-2.0 license and all six workflow actions are unpinned.
78%
Total Score
100
100
86
67
The artifact contains a license file, but it identifies Apache-2.0 while the manifest declares MIT. The release is licensed, yet the mismatch creates an avoidable legal and transparency concern.
The project uses Composer build tooling, but no security-scanning tools were detected. The missing scanning is a modest process gap rather than evidence of abandonment.
The repository has no security policy. For an admin interface handling compliance operations, the absence reduces disclosure transparency.
Both workflows were analyzed successfully with no untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned and one workflow grants top-level write permissions, creating workflow reproducibility and least-privilege concerns without an observed untrusted trigger.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.