The package includes tests, a changelog, release notes, a clear MIT license, and a non-archived repository. Its workflow actions are unpinned and the project has no security policy, leaving avoidable build and maintenance concerns despite recent activity.
70%
Total Score
83
100
88
75
The package is only 51 days old, with 25 releases clustered in that period and a median interval of 0 days. This shows active iteration but provides little long-term maintenance evidence.
All 20 recent commits came from one contributor, with one active contributor in the period. Organization backing helps with handoff potential, but no second active contributor is shown.
The project uses Composer for builds, but no security scanning tooling is reported. The missing scanning coverage is a modest transparency and maintenance concern.
The repository has no security policy. For a library handling application integrations, this leaves vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous audit findings, but both action references are unpinned. That weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~8|~9|~10|~11|~12|~13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.