The repository includes tests, release notes, and a clear license. All 22 workflow actions are unpinned, and the project has no security scanning or security policy, leaving avoidable maintenance gaps.
64%
Total Score
50
83
50
The package is less than a day old and has only two releases, so there is not yet enough history to show dependable maintenance or release practices.
No commits or active maintainers were recorded in the last three months, which is consistent with the package's very recent creation but does not yet demonstrate sustained maintenance.
The repository has no security policy, leaving disclosure and security-maintenance expectations undocumented for a server package.
Version v0.1.1 is below 1.0, indicating an early API and implementation stage despite not being marked as a prerelease.
All 22 analyzed action references are unpinned, and one release workflow has top-level write permissions. The low-confidence cache-poisoning finding is hygiene rather than a severe risk, but the overall workflow setup needs tightening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/reverb Version ^1.0 | — | — |
illuminate/redis Version ^10.47|^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^10.47|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.47|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.47|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.