Three months without commits or active maintainers weakens confidence in ongoing maintenance. The repository has solid documentation, tests, release notes, licensing, and static analysis, but its workflows use an unpinned container image and lack a dedicated security policy.
68%
Total Score
88
100
89
67
The package has existed for about 6 years with 19 releases and a latest release on March 31, 2026. Only one release in the last 12 months suggests a slower current cadence, though the latest release is recent.
There were zero commits and zero active maintainers in the last three months. The recent release partly offsets this, but the lack of current development activity is a meaningful maintenance concern.
The repository has 4 stars and 1 fork. This is limited adoption evidence, but popularity is supporting context and does not outweigh the stronger maintenance and transparency signals.
The repository has no dedicated security policy. Its README provides a security contact, which partly compensates, but the missing formal policy reduces disclosure transparency.
All four workflows were analyzed with no untrusted checkout or script-injection findings, but all nine action references are unpinned and the audit found a high-confidence unpinned container image. The workflows avoid top-level write permissions, which limits the impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.