The package is clearly identified, MIT-licensed, documented, and backed by an organization with repository tests and a security policy. Its stable release and modest dependency set support adoption, while the limited activity record leaves less maintenance evidence.
65%
Total Score
67
100
94
67
The package runs a post-autoload-dump script during installation. This is a supply-chain and installation-behavior consideration, though the signal does not show that the script is harmful.
The package has six releases since June 2023, with one release in the last 12 months and the latest released in March 2026. This is a modest cadence rather than evidence of abandonment.
The repository recorded zero commits and zero active maintainers in the last three months. Although the recent release and push provide some counterevidence, the current maintenance record is thin.
There are no open issues and two open pull requests, but no issues or pull requests were merged in the last month. This offers limited evidence of active project response.
All three workflows were analyzed, but all nine action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 || ^13.0 | — | — |
phpstan/phpstan Version ^2.1 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
worksome/request-factories Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.