The package is documented, licensed, and backed by an organization, with a recent release and a stable version line. Maintenance is currently thin, with only two recent commits from one contributor and no security policy; the workflow also uses an unpinned action.
70%
Total Score
67
100
93
75
The package is 655 days old, has 19 releases, and was released recently, but only two releases occurred in the last 12 months. This indicates ongoing publication with a slower recent cadence.
One contributor made all two recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown, leaving current maintenance concentrated.
Only two commits were recorded in the last three months, so maintenance activity is limited despite the recent release.
The repository has no SECURITY policy. This is a transparency and vulnerability-reporting gap, though it is not by itself evidence of abandonment.
The sole workflow was fully analyzed with no audit findings and no untrusted checkout or script-injection sink; its pull_request_target trigger is ordinary. However, its one action reference is unpinned, which is a workflow hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dystcz/dystore-api Version ^1.0.15 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.