The MIT license, README, tests, changelog, and matching repository provide good transparency for consumers. Workflow references are all unpinned, and the repository has no security policy or scanning, leaving maintenance hygiene moderate.
76%
Total Score
50
93
50
The repository recorded zero commits and zero active maintainers during the last three months. The recent release provides some compensation, but the short-term lack of source activity is a maintenance caution.
Composer is used for the build, but no security scanning tools are configured. Build tooling is present, while security-process coverage is limited.
The repository has no security policy. For a small Laravel package this is a transparency gap, though it is not evidence of unsafe code by itself.
The single workflow was fully analyzed with no injection or high-severity findings, and it has no top-level write permissions. However, all three action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^7.0|^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.