Documentation, tests, licensing, and a matching repository are solid. The project has no security policy or scanning, and its only workflow uses unpinned actions with broad write access; pin this exact version if adopting.
58%
Total Score
50
86
67
This is the sole release, published about 16 months ago, with no releases in the last 12 months. That leaves maintenance and compatibility uncertain for a Laravel dependency.
The repository recorded no commits and no active maintainers in the last 3 months. Combined with the single-release history, this is meaningful abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance weakness, though not a severe risk by itself.
No repository security policy was found. For a wallet package handling balances and transactions, the absence reduces reporting transparency.
The single analyzed workflow has top-level write permissions and all 4 action references are unpinned. No untrusted checkout, injection, or high-severity audit findings were present, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.