Clear documentation, tests, and release notes make integration easier. The package is licensed and backed by an organization, but its limited release and recent commit history leave maintenance continuity uncertain.
62%
Total Score
75
100
93
100
This is the only release, published about eight months ago, so there is little release history to demonstrate sustained maintenance. The repository's release notes provide some transparency but do not establish a continuing cadence.
There were no commits and no active maintainers in the three months before collection. That gap is meaningful for a package with only one release and weakens confidence in ongoing maintenance.
All four workflows were analyzed, but all 18 action references are unpinned, two workflows grant top-level write access, and a high-confidence bot-conditions finding reports spoofable actor context. These are workflow supply-chain hygiene concerns, though no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^11.0|^12.0 | — | — |
accelade/accelade Version ^1.0.0 | — | — |
illuminate/support Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.