The package is documented, licensed, and backed by repository tests and release notes. Maintenance is uncertain after no commits in three months, while high-confidence workflow concerns and fully unpinned actions weaken release hygiene.
62%
Total Score
50
100
100
50
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. Three workflows also grant top-level write permissions, so release automation has weaker-than-desired controls.
The package runs a post-autoload-dump script during installation. This is common Composer behavior but adds execution during dependency installation and warrants ordinary care.
One registry maintainer is a narrow publishing base for a user-owned project, so continuity depends heavily on one person.
The package and repository are owned by the same individual account, which is consistent ownership but offers no organizational backing to absorb maintainer absence.
The repository recorded zero commits and zero active maintainers over the last three months. For a young package this is a meaningful maintenance concern, despite a recent push timestamp.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.7 | — | — |
illuminate/bus Version ^11.0||^12.0||^13.0 | — | — |
illuminate/http Version ^11.0||^12.0||^13.0 | — | — |
illuminate/cache Version ^11.0||^12.0||^13.0 | — | — |
illuminate/queue Version ^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.