Maintenance is active, with 17 releases in the last year and commits from two contributors in the last three months. The workflow has broad permissions and unpinned actions, while security guidance is absent; prefer the named replacement for new projects.
58%
Total Score
83
81
67
Packagist marks the whole package abandoned and names grafite/formmaker as its replacement. Active releases and recent repository activity partly compensate, but relying on the replacement is safer for new work.
One contributor made 13 of 14 recent commits, or about 93%, leaving the project dependent on a single primary contributor. Organization backing provides some handoff capacity but does not remove the concentration concern.
Composer is used for builds, but no security scanning tooling was detected. The missing scanning is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy. This makes vulnerability reporting and response expectations less clear for a package used in applications.
The single workflow was fully analyzed with no reported audit findings, but all three action references are unpinned and the workflow grants top-level write permissions. Those are avoidable supply-chain and least-privilege weaknesses without an untrusted trigger or checkout.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
matthiasmullie/minify Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.