The package is clearly licensed and documented, with repository tests, release notes, and a small dependency footprint. It lacks a security policy and automated security scanning, which leaves maintenance safeguards weaker than they could be.
68%
Total Score
50
100
94
75
The package and repository are owned by the same individual account. This supports clear ownership, but provides less organizational continuity than a backed project.
There were no commits and no active maintainers in the last 3 months. The recent release provides some compensating evidence, but the short-term development pause still raises maintenance concern.
The project uses Composer, but no security scanning tools were detected, leaving dependency and build-risk checks less comprehensive.
The repository has no security policy, making its process for reporting and handling vulnerabilities unclear.
Both workflows were analyzed successfully and have no untrusted checkouts, injection findings, or top-level write permissions. However, the CI uses five unpinned references, including a high-confidence high-severity unpinned container image, so build inputs are not fully reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.