The package is well documented, tested, actively released, and backed by recent repository work. Most workflow references are unpinned and no security policy is published, leaving avoidable maintenance and supply-chain hygiene gaps.
82%
Total Score
88
100
100
67
Four contributors were active in three months, but one contributor made about 69% of commits. The remaining contributors provide some continuity, so this is a mild concentration concern rather than a severe risk.
The repository has no published security policy, which leaves vulnerability-reporting expectations unclear for a database integration package.
All seven workflows were analyzed with no reported audit findings or untrusted-checkout/script-injection paths. However, 28 of 29 action references are unpinned and two workflows have top-level write permissions, creating avoidable workflow hygiene and token-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version 5.1.*|5.2.* | — | — |
illuminate/database Version ~5.1.20|5.2.* | — | — |
yajra/laravel-pdo-via-oci8 Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.