67%
Total Score
caution
A brand-new package has no maintenance track record yet and lacks a repository security policy.
The linked repository is owned by a user account rather than an organization, so the project has no demonstrated organizational backing. The package-to-repository relationship is nevertheless supported by the matching name and README mention.
The package has seven releases, all published within the same day, and is effectively 0 days old. This shows active initial publishing but provides no long-term maintenance track record.
Composer is used for builds, but no security scanning tooling is present. This is a modest transparency and hygiene gap rather than a severe dependency risk.
The repository has no security policy. For a package intended to serve a health-check route, this leaves vulnerability reporting and response expectations unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.