The README, tests, MIT licensing, and organization-backed source provide a solid integration and ownership foundation. GitHub Actions use read-only permissions but all four action references are unpinned, and no security scanning tool is reported.
70%
Total Score
100
81
75
The package is only 48 days old and has two releases, with a median interval of about 6 days. This shows initial activity but leaves long-term maintenance unproven.
Composer build tooling is present, but no security scanning tool was detected. For a Laravel package handling authorization, enrollment, and certificates, this is a modest transparency and maintenance gap.
v0.2.0 is not a stable major release, so its API and behavior may still change materially. It is not marked as a prerelease, which provides limited compensation.
Both workflows were fully analyzed, use read-only permissions, and have no reported high- or medium-severity findings. However, all four action references are unpinned, leaving avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^13.0 | — | — |
illuminate/routing Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/database Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.