It has a matching repository, MIT licensing, tests, and a small dependency surface. The narrow scope may limit exposure, but there is little evidence of ongoing support for new framework versions.
53%
Total Score
0
100
75
50
The package has had four releases, but none in roughly four years; this materially increases the risk that compatibility issues will remain unresolved.
The repository recorded no commits and no active maintainers in the three months before collection, reinforcing the evidence of long-term inactivity.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities, though this is a secondary concern for a small package.
The workflow uses read-only permissions and has no detected audit findings or untrusted execution paths, but both action references are unpinned, leaving avoidable reproducibility and update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.