This is a healthy, mature release with a long release history, a recent release, stable versioning, active repository maintenance, organizational backing, multiple active contributors, and strong package/repository documentation and test coverage. The package is not deprecated or archived, has a clear MIT license, no install-time lifecycle scripts, and uses Dependabot security tooling. The main reservations are the absence of a repository security policy and inconsistent GitHub Actions token-permission declarations, including write permissions in two workflows; these are repository hygiene concerns but do not outweigh the substantial evidence of active maintenance and transparency.
90%
Total Score
100
100
100
70
One of five workflows uses pull_request_target, which warrants review because that trigger can elevate workflow privileges; however, no untrusted checkouts or script-injection patterns were detected.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
Three workflows lack top-level permission declarations and two declare write permissions, so the repository has weaker-than-ideal least-privilege workflow hygiene despite otherwise active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.