The MIT license, stable versioning, release notes, and organization-backed repository provide a clear baseline. Dependabot is enabled, but workflow references are unpinned and no security policy is published.
61%
Total Score
75
75
50
The package has 20 releases since November 2021, but none in the last 12 months; its latest release was about 19 months ago, indicating stalled release activity.
The repository recorded no commits and no active maintainers in the last 3 months, despite a recent repository push timestamp; this provides weak evidence of current maintenance.
The repository name matches the package, which supports the linkage, although the README does not mention the package name; this is a minor transparency gap.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for consumers and maintainers.
All 7 analyzed action references are unpinned, which weakens reproducibility and update control. The audit found no untrusted checkouts, script injection, or high-severity findings, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version >=6.0 <13.0 | — | — |
symfony/http-kernel Version ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
illuminate/validation Version >=6.0 <13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.