The package includes a clear README, MIT licensing, repository tests, and release notes. It has no install-time scripts, and the workflow audit completed without high-severity findings.
67%
Total Score
67
93
75
The registry has one maintainer, and the repository is user-owned rather than organization-owned, so there is little visible maintenance redundancy.
One contributor made all 15 recent commits, leaving the project dependent on a single person for ongoing maintenance and succession.
Composer build tooling is present, but no security-scanning tools were detected, leaving security maintenance less visible.
The repository has no security policy, which is a transparency gap for an audit-log package that handles sensitive application history.
The workflow audit completed fully with no high- or medium-severity findings and no untrusted checkout or script-injection paths. However, all 8 action references are unpinned, weakening build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/routing Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.