It has a clear README, release notes, repository tests, and regular recent releases. Organization backing and two active contributors help offset the small project footprint.
72%
Total Score
100
100
100
50
The repository has no security policy. That reduces disclosure transparency, although the available tooling and active repository provide some compensating project hygiene.
The audit found a high-confidence template-injection issue in release.yml, top-level write permissions in two workflows, and all 10 action references unpinned. No untrusted checkout or dangerous trigger was present, so this is a significant hygiene concern rather than a standalone critical risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/queue Version ^11.0||^12.0||^13.0 | — | — |
illuminate/support Version ^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.