The repository includes tests, release notes, and a clear MIT license, while dependencies and install behavior are modest. Workflow references are all unpinned, one release workflow grants broad write access, and no security policy or scanning is present.
67%
Total Score
50
100
88
75
The package is 141 days old with four releases, but all releases occurred on the same day and there has been no later release. That concentrated launch history provides limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, despite the package being only 141 days old. This is meaningful evidence of stalled maintenance, though not abandonment by itself.
Composer build tooling is present, but the repository has no detected security scanning tools. That reduces automated coverage for a package intended for application dependencies.
The repository has no security policy, leaving reporting and response expectations undocumented. This is a transparency gap rather than evidence of an unsafe release.
The audit analyzed both workflows and found no untrusted checkout or script-injection paths, but all five action references are unpinned and one release workflow has top-level write permissions. These are hygiene concerns; the broad token is not paired with an identified untrusted trigger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.