Clear documentation, repository tests, release notes, and an MIT license support dependable integration. The source project is active in practice, though its very short history leaves limited evidence about long-term maintenance.
78%
Total Score
100
88
50
This is a newly published package with only two releases within about one day, so it has little demonstrated release history despite the current release notes.
The repository uses Composer build tooling, but no security-scanning tool was detected, leaving a modest security-process gap.
The repository has no security policy. This does not show a defect in the package, but it reduces transparency about how vulnerability reports are handled.
Both workflows were analyzed without audit failures, untrusted checkouts, or script injection. However, all 11 action references are unpinned and one workflow grants top-level write permissions, creating avoidable workflow supply-chain and permission hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/log Version ^12.0|^13.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
illuminate/cache Version ^12.0|^13.0 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.