The release includes tests, release notes, a clear MIT license, and an active build process. Its active repository and rapid releases are outweighed by Packagist marking this package abandoned and naming bladeuix/components as the replacement.
22%
Total Score
83
100
83
75
Packagist marks the entire package as abandoned and names bladeuix/components as its replacement, making this release a poor dependency target despite other healthy signals.
One contributor made all 52 commits in the last 3 months, leaving no demonstrated contributor redundancy. Organization backing provides some continuity, but no second active contributor is shown.
The repository has only 2 stars and no forks or watchers, so there is little external evidence of adoption or community support.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were analyzed successfully with no reported audit findings or untrusted checkout and script-injection paths. However, all 4 action references are unpinned, which is a supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0 | ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.