The README still contains placeholder text, and all four workflow actions are unpinned. Tests, release notes, an MIT license, and an unarchived repository provide useful transparency, but do not offset the maintenance risk.
38%
Total Score
0
81
50
The last release was on September 8, 2021, and there were no releases in the following five years. This is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers during the last three months of collection, consistent with the long release hiatus.
Composer build tooling is present, but no security-scanning tool was detected. That modestly reduces supply-chain transparency without proving the release is unsafe.
The repository has no security policy, leaving no documented reporting process. This is a transparency gap, though it is secondary to the package’s lack of recent maintenance.
All four analyzed action references are unpinned, weakening build reproducibility and exposing workflow dependencies to change. The audit found no untrusted checkouts, script injection, or high-severity issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.