Healthy and reasonable to use, with a clear repository, permissive licensing, tests, release notes, and recent releases. The main caveat is that no commits or issue activity were recorded in the last three months, despite the repository remaining active recently.
78%
Total Score
63
100
100
90
Only one registry account has publish access, which is a limited publishing base, but the repository and release activity provide compensating evidence of an established project.
The repository is owned by an individual rather than an organization, so the single registry maintainer represents a relatively narrow formal backing base.
No commits or active maintainers were recorded in the last three months, which is a maintenance concern, although the repository was pushed recently and the package has a recent release.
All three workflows lack top-level token permission declarations. No workflow has declared top-level write access, but explicit least-privilege permissions would improve CI transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
blade-ui-kit/blade-icons Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.