The MIT license, substantial README, and matching repository make adoption easier. All two workflow actions are unpinned, and no security policy or security scanning is present.
67%
Total Score
100
79
75
This is a young package with one release, published about 295 days ago, and no subsequent releases. That leaves limited evidence of ongoing maintenance or compatibility work.
Composer is used as the build tool, but no security-scanning tooling is configured. For a dependency package, that is a modest transparency and maintenance gap.
The linked repository is not archived, so it remains available for maintenance; however, its last push was on the original release date, which provides no evidence of later activity.
The repository has no security policy. This does not show a vulnerability, but it gives consumers no documented reporting or response process.
The single workflow was fully analyzed with no dangerous audit findings or untrusted checkout, but both of its two action references are unpinned. The missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0 | — | — |
illuminate/database Version ^11.0|^12.0 | — | — |
illuminate/validation Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.