The package is small and focused, with clear documentation, tests, licensing, and a recent compatibility release. Maintenance activity has paused recently, while workflow safeguards need tightening before relying on it long term.
61%
Total Score
75
100
94
100
The package has existed for about 8 years with 17 releases, but only one release occurred in the last 12 months and the median interval is about 178 days. This suggests a slow but established release cadence.
The repository recorded zero commits and zero active maintainers in the past three months. The recent release partly offsets this, but the lack of ongoing activity raises maintenance risk.
All 9 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection sink, so this is workflow hygiene risk rather than a severe release risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0 | ^10.0 | ^11.0 | ^12.0 | ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.