The package includes tests, a README, and a stable MIT license. Organization backing and a recent registry release help, but security policy coverage is limited.
66%
Total Score
75
100
86
75
The package has 9 releases over about 5 years, with one release in the last 12 months and a median interval of about 160 days. This indicates ongoing but relatively infrequent maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. Even with a recent registry release, this suggests limited current development activity.
Composer build tooling is present, but no security scanning tooling was detected. This is a maintenance and transparency gap, though it is not severe by itself.
The repository has no security policy. That leaves vulnerability reporting and disclosure expectations unclear for a package intended for application integration.
The single workflow was fully analyzed with no audit findings or dangerous triggers, but both referenced actions are unpinned. Unpinned actions weaken build reproducibility and supply-chain transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8|^9|^10|^11|^12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.