The repository includes tests, a README, matching release notes, and organization backing. Unpinned workflow actions, no security policy, and a thin recent activity record leave meaningful maintenance and hygiene concerns.
61%
Total Score
75
100
79
50
The package runs a post-autoload-dump lifecycle script during installation. This is a supply-chain surface that merits review, but the signal alone does not show harmful behavior.
The package has existed for about 832 days with four releases and two releases in the last 12 months, but the median release interval is about 260 days. This indicates intermittent rather than strong ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. Although the latest release was recent, the absence of recent source activity raises abandonment risk.
The project uses Composer build tooling, but no security scanning tools were detected. For a small package this is a hygiene gap rather than evidence of unsafe code.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, even though it does not by itself show a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/queue Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.