The package is well documented and backed by recent repository work from multiple contributors. Its missing security policy and fully unpinned workflow actions reduce transparency and build reproducibility, but the repository has tests and no dangerous workflow findings.
78%
Total Score
100
100
88
75
This is a young package, released four times over about 86 days with releases roughly every 10 days, showing active early maintenance but limited long-term history.
Composer build tooling is present, but no security scanning tool was detected, leaving security-process coverage weaker than the rest of the project tooling.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent for a package handling invitations and anti-abuse features.
All three workflows were analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and two use read-only permissions. However, all eight action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.92 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.