The repository includes tests, release notes, a security policy, and dependency scanning. Its install hook and broad workflow write permission deserve routine review, while the small audience is not itself a blocker.
82%
Total Score
75
100
100
67
A post-autoload-dump install-time script runs during Composer installation. This is a review point because installation executes package code, though the signal provides no evidence that the script is unsafe.
Two contributors are active, but one accounts for 7 of 9 recent commits, leaving maintenance concentrated in a small contributor base.
Both workflows were analyzed successfully, all 5 action references are pinned, and no audit findings or untrusted-code sinks were reported. One workflow grants top-level write permissions, which is broader than necessary but not dangerous without an untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.