The project has stopped committing over the last three months, and all six workflow actions are unpinned. Clear licensing, tests in the repository, recent release notes, and an active repository provide useful counterweight.
62%
Total Score
33
50
88
75
There were no commits and no active maintainers in the last three months, a concrete sign that development has recently stalled despite the earlier release cadence.
Thirteen runtime dependencies, including Laravel components and data-processing libraries, create a meaningful dependency surface but are coherent with the package's ETL functionality.
Only one registry account has publish access. That is a modest publishing bus-factor concern for a user-owned project, though repository activity provides some compensation.
The repository is owned by a user account rather than an organization, so the single publisher and small maintainer base are not backed by visible organizational ownership.
Composer build tooling is present, but no security scanning tools were detected, leaving security-quality checks less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/queue Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
halaxa/json-machine Version ^1.2 | — | — |
illuminate/database Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.