Gather insights and verify phone numbers from multiple third-party providers.
72%
Total Score
caution
Usable with caveats: active releases and tests offset stalled commits and weak workflow hygiene.
The package uses a post-autoload-dump Composer script. This adds install-time behavior, but the provided evidence does not show it is unusually risky or excessive.
There were no commits and no active maintainers during the last three months, despite the recent release history; this suggests current development may have paused.
Composer is used for builds, but no security scanning tools are reported. The missing scanning is a modest transparency and maintenance concern rather than evidence of an unsafe release.
The repository has no security policy, reducing clarity about vulnerability reporting and maintenance response.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all five action references are unpinned, which leaves avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.