Documentation, licensing, tests in the repository, and release notes are in place. No commits or issue activity were recorded in the last three months, while the workflow uses an unpinned action and lacks a security policy.
64%
Total Score
67
100
94
67
No commits and no active maintainers were recorded during the last three months. This is a maintenance warning, although the recent release history provides some compensating evidence.
There are no open issues or pull requests and no issue or pull-request activity in the last month; this is consistent with a quiet project but provides little evidence of active support.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanner is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a package that handles Slack requests and signatures.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, but its only action use is unpinned and it has no top-level permissions block. These are limited workflow-hygiene concerns, not severe risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/queue Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/config Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.