Documentation is strong, with repository tests, a changelog, release notes, and a matching source repository. The project has no security policy or automated security scanning, so future maintenance is harder to verify.
58%
Total Score
75
50
The package has had no release in about two and a half years, with all four releases clustered within minutes and none in the last 12 months. This is a meaningful maintenance and abandonment concern.
Composer build tooling is present, but no security-scanning tools were detected. That leaves vulnerability checks less visible and contributes to maintenance uncertainty.
The repository has no security policy, which reduces transparency around vulnerability reporting and maintenance expectations. This is a modest concern rather than evidence that the package is unsafe.
Both workflows were analyzed successfully, with no untrusted checkout or script-injection findings, but all four action references are unpinned and the audit found a high-confidence, high-severity unpinned container image.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0 | — | — |
illuminate/filesystem Version ^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.