Testing, documentation, licensing, and release notes provide a reasonable base. However, the package has seen no registry release for over five years and no repository commits for over four years, so pinning it carries meaningful maintenance risk.
45%
Total Score
0
75
67
The package has had no release for more than five years, despite 16 releases overall; this prolonged inactivity is a substantial maintenance concern.
The repository recorded no commits or active maintainers in the last three months, and its last push was more than four years ago, reinforcing the abandonment risk.
The repository has no security policy, which weakens vulnerability-reporting transparency, although this is a secondary concern compared with the maintenance slowdown.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all three action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ~6.0|~7.0|~8.0 | — | — |
illuminate/session Version ~6.0|~7.0|~8.0 | — | — |
illuminate/support Version ~6.0|~7.0|~8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.