The project has enough recent activity and release documentation to support adoption. Keep an eye on its infrequent release cadence and workflow hygiene, especially unpinned actions and a low-confidence cache warning.
78%
Total Score
100
100
93
50
The package has released for nearly four years, but only one release appeared in the last 12 months and the median interval is about 228 days. This indicates slower maintenance rather than abandonment, especially alongside a recent release.
No security policy was found in the repository, which weakens the documented process for reporting vulnerabilities. This is a transparency gap, not evidence that the package is unsafe.
All five workflow actions are unpinned, which weakens build reproducibility, and the auditor reported a low-confidence cache-poisoning pattern. The workflow has no untrusted checkout, script injection, or broad top-level write permission, so this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/log Version ~11.0 || ~12.0 || ~13.0 | — | — |
illuminate/config Version ~11.0 || ~12.0 || ~13.0 | — | — |
illuminate/contracts Version ~11.0 || ~12.0 || ~13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.