Tests, a substantial README, and release notes improve adoption confidence. The missing security policy and eight unpinned workflow actions leave modest transparency and build-reproducibility gaps.
82%
Total Score
100
100
88
67
The package is young at 92 days old with two releases and a median interval of about 68 days. This is limited maturity, though repository activity provides some compensation.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest supply-chain hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Both workflows were fully analyzed with no dangerous sinks or audit findings, but all eight action references are unpinned and one workflow grants top-level write access. These are build-reproducibility and permission-hygiene weaknesses, not severe risks on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.