Documentation, repository tests, and a security policy improve confidence. The project has little history, and its workflow references are not pinned.
68%
Total Score
50
100
83
88
The registry namespace and repository owner are connected, but the owner is an individual account rather than an organization. This provides ownership context without strong evidence of a broader maintenance team.
The package is only 45 days old with three releases, and the median interval is about 17 hours. This shows active initial development but provides too little history to establish long-term maintenance.
The repository has zero stars, forks, and watchers. The project is very young, so this is weak supporting evidence rather than a standalone abandonment signal.
Version v0.3.0 is not a stable major release, so the public API may still change. It is not marked as a prerelease, which provides some compensation.
The sole workflow was fully analyzed with no dangerous sinks or audit findings, but all 12 action references are unpinned. That leaves avoidable build-integrity exposure despite the otherwise clean audit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^12.61.1 || ^13.12.0 | — | — |
illuminate/http Version ^12.61.1 || ^13.12.0 | — | — |
illuminate/cache Version ^12.61.1 || ^13.12.0 | — | — |
illuminate/queue Version ^12.61.1 || ^13.12.0 | — | — |
illuminate/console Version ^12.61.1 || ^13.12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.