Documentation, tests, licensing, and release notes are all present. CI is fully audited, but its ten external actions are unpinned, leaving avoidable build-integrity exposure.
68%
Total Score
67
100
94
100
The repository is owned by a GitHub user rather than an organization, so the concentrated contributor activity is not visibly backed by a broader institutional maintenance team.
The package is only 47 days old with two releases, so its maintenance history and long-term stability are not yet established. Releases were about four days apart, which shows initial activity but not maturity.
One contributor made 12 of 14 recent commits, or about 86%, while two others made one each. That concentration leaves the project dependent on one primary maintainer.
All three workflows were analyzed successfully with no untrusted checkouts, script injection, or auditor findings, and none grants top-level write access. However, all 10 referenced actions are unpinned, which weakens build reproducibility and action supply-chain protection.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.