The repository includes tests, release notes, a license, and a security policy. Organization backing helps offset the single-contributor base, but all 12 workflow actions are unpinned and the install script warrants care.
70%
Total Score
83
94
75
The package runs a post-autoload-dump install-time script. This is a supply-chain execution surface, though the signal does not show a dangerous script or malicious behavior.
This is the first release and the package is 0 days old, so there is no release track record from which to judge long-term stability.
All 32 recent commits came from one contributor, creating a real continuity risk; organization ownership provides some handoff capacity but no second active contributor is shown.
All three workflows were analyzed with no untrusted checkout, script injection, or high-severity findings. However, all 12 action references are unpinned, leaving workflow dependencies exposed to moving revisions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^12.0|^13.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/view Version ^12.0|^13.0 | — | — |
illuminate/cache Version ^12.0|^13.0 | — | — |
illuminate/queue Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.