The repository includes tests, documentation, and a clear license, which supports adoption. Workflow safeguards are weak, with unpinned actions and a high-confidence bot-condition finding; the project also has limited visible ownership capacity.
58%
Total Score
50
88
50
Only one registry account has publish access, and the repository is user-owned rather than organization-backed. This leaves a thin visible publishing and maintenance base.
The package is about 340 days old but has only two releases, both within the same release period, indicating limited release maturity and an uncertain maintenance pattern.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance concern for a package intended to manage application secrets.
The repository has no SECURITY.md or other security policy. For a library that handles Vault and application secrets, this weakens vulnerability-reporting transparency.
The assessed version is v0.1.0-alpha.2, and all recent releases are prereleases. This signals an API and maintenance profile that may still change substantially.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.