The MIT license, tests, and changelog support straightforward adoption. The workflow audit found no dangerous patterns, though its two actions are unpinned and no security policy is published.
84%
Total Score
83
100
89
75
The package and repository share the Skeylup owner, and the repository is user-owned rather than organization-owned; the two active contributors therefore provide useful but limited backing.
The repository has one star and no forks or watchers. This provides little evidence of broad adoption, but popularity is supporting evidence and does not outweigh the active maintenance signals.
Composer is used for builds, but no security scanning tools are reported. That is a modest transparency and monitoring gap rather than evidence of abandonment.
The repository has no published security policy, leaving vulnerability reporting and response expectations unspecified.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, so their contents can change outside a release review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/log Version ^8.65|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/http Version ^8.65|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
monolog/monolog Version ^2.0|^3.0 | — | — |
illuminate/queue Version ^8.65|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^8.65|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.