The repository has no security policy or security scanning, and both workflow actions are unpinned. It is a young package with no recorded commits in the past three months, despite a recent push and a matching repository.
62%
Total Score
50
100
88
75
This package is only 47 days old with two releases, so its maintenance record is still too short to establish long-term reliability; the recent v1.0.1 release is mildly reassuring.
No commits or active maintainers were recorded in the past three months. Because the package is only 47 days old and was pushed recently, this is a limited but meaningful warning rather than evidence of abandonment.
Composer is used as a build tool, but no security scanning tools are configured. That weakens project hygiene without showing that the package is unsafe to depend on.
The repository has no security policy, leaving no documented path for reporting or handling vulnerabilities.
The single workflow was fully analyzed with no reported audit findings and scopes permissions at job level, but both of its two action references are unpinned. This leaves avoidable supply-chain reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.