The repository includes tests, a changelog, and security scanning, but its workflow references are not pinned. Pin v2.0.0 only with a plan to replace it if maintenance does not resume.
58%
Total Score
50
100
94
67
There were no commits and no active maintainers in the last three months, a meaningful sign that maintenance may have stalled after the initial release.
The package is 185 days old but has only two releases, both published within minutes of each other, providing little evidence of an established release cadence.
No security policy is present, which weakens the project's transparency about reporting and handling vulnerabilities.
All four analyzed action references are unpinned, which weakens build reproducibility. The high-confidence template-injection finding is a workflow hygiene concern, but there are no untrusted checkouts or script-injection findings to corroborate a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.