Comprehensive tests, a clear README, and a matching source repository improve confidence. Maintenance is concentrated in one contributor, and all four workflow actions are unpinned; the missing security policy is another modest transparency gap.
78%
Total Score
67
100
100
75
The repository is owned by the 3neti user account rather than an organization, so there is no provided organizational backing to offset the concentrated contributor base.
All five recent commits came from one contributor, leaving maintenance highly concentrated and increasing abandonment or handoff risk.
The repository has no security policy, which is a modest transparency gap for a package that may handle voucher and settlement data.
The single workflow is fully analyzed, uses read-only permissions, and has no dangerous sinks or audit findings. However, all four action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/config Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/collections Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.