The repository is clearly tied to the package and has tests, release notes, and organizational backing. Maintenance has slowed substantially, while workflow references remain unpinned and no security policy is present.
62%
Total Score
75
100
88
67
Only two releases exist, with none in the last 12 months and the latest published more than three years ago. This is a meaningful maintenance concern despite the repository having a later push.
There were no commits or active maintainers in the last three months, which indicates limited current maintenance capacity and reinforces the stale release history.
Composer is used for builds, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than a severe concern.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
The workflow audit completed cleanly with read-only permissions and no dangerous findings, but both analyzed action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/routing Version ^8.0|^9.0|^10.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0 | — | — |
illuminate/contracts Version ^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.