Healthy and reasonable to adopt, with strong repository activity and project backing. It is very new with only two releases, and its install workflow includes a post-autoload script, so production adoption should still include normal review and upgrade testing.
78%
Total Score
100
100
89
80
A post-autoload-dump install-time script is present, which adds execution during dependency installation and merits review, though the signal does not show a dangerous workflow or malicious behavior.
The package is only 40 days old and has two releases, both clustered on its first release day, so long-term maintenance and release consistency are not yet demonstrated.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but the package is only 40 days old and popularity is not decisive against the observed maintenance activity.
One workflow has top-level write permissions while the other is read-only; write access is a workflow-hardening concern, though no other dangerous workflow behavior was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0||^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.