The package includes tests, a changelog, a license, and security tooling. Its GitHub workflows use unpinned actions and contain a high-confidence bot-condition warning.
61%
Total Score
50
94
75
This is a young package, 107 days old, with only one release and no established release cadence. That limits evidence of long-term maintenance but does not indicate abandonment by itself.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a package with only one release.
All 11 action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.