This release appears suitable to depend on: it is a stable 1.3.0 release with nine releases over 161 days, recent repository activity, merged pull requests, a non-archived source repository, repository tests and changelog coverage, and clear MIT licensing. The main reservations are the young project age, low popularity, concentrated recent commits, absent security policy and security-scanning tooling, and incomplete GitHub Actions permission declarations; however, the organization-owned repository, active second contributor, safe workflow analysis, and ongoing release cadence provide meaningful mitigation. The package artifact is minimal and omits its README, tests, and changelog, but those materials are present in the source repository, so this is primarily a distribution-hygiene gap rather than an abandonment signal.
82%
Total Score
90
100
89
80
Two contributors were active, but the top contributor made about 78% of recent commits. This is concentrated activity, though organization ownership provides some ability to hand maintenance off.
The repository has seven stars and two forks, indicating limited adoption. Popularity is only supporting evidence, so this modest reach lowers confidence in maturity but does not by itself make the package unsafe to use.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a security-hygiene gap, although it is not evidence of abandonment.
The repository has no security policy. This reduces disclosure transparency and is a genuine project-hygiene gap, particularly for a package intended to be used as a dependency.
One workflow lacks top-level permissions and the release workflow grants top-level write access. These declarations are less restrictive than ideal and increase CI permission risk, although the separate workflow-risk analysis found no dangerous workflow pattern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/cache Version ^10.0|^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.15.2 || ^8.0.1 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.