Documentation, tests, and a clear MIT license make integration easier. Organization backing and a non-archived repository help, but the project is too new to establish durable maintenance; its two workflow actions are also unpinned.
62%
Total Score
75
100
86
67
This is the first release, published today, so there is no release cadence or track record yet. That limits confidence in long-term maintenance rather than showing abandonment.
The repository recorded zero commits and zero active maintainers in the past three months. Because the package was published today, this is mainly an unproven-maintenance concern rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tools were detected. That is a modest repository hygiene gap, not a release-blocking issue.
The repository has no security policy. For a package handling backend and frontend service keys, that reduces transparency for reporting vulnerabilities.
The workflow audit completed fully with no dangerous triggers or audit findings, but both analyzed action references are unpinned. That leaves workflow dependencies exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^10.0|^11.0|^12.0|^13.0 | — | — |
yatmo/yatmo-php Version ^1.1 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.