The package has a clear README, an MIT license, repository tests, and a changelog. Its maintenance record is too new to establish durability, and the workflows use broad permissions and unpinned actions.
62%
Total Score
50
94
67
The package is only 0 days old with two releases, so there is not enough history to demonstrate sustained maintenance or release reliability.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Because the project is brand new, this limits evidence of ongoing maintenance rather than proving abandonment.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
All 12 analyzed action references are unpinned, and three workflows grant top-level write permissions. The audit found no untrusted checkout or script-injection paths, so this is workflow hygiene risk rather than a severe exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
jaybizzle/crawler-detect Version ^1.2 | — | — |
mobiledetect/mobiledetectlib Version ^2.8.34||^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.