All eight workflow references are unpinned, and the repository has no security policy. A repository test suite, matching package source, MIT license, and Dependabot provide useful transparency and basic project hygiene.
65%
Total Score
50
100
93
75
This is the first release, published today, so there is no release track record to demonstrate sustained maintenance or stability.
No commits or active maintainers were recorded in the last three months. Because the package is brand new, this is mainly an unproven maintenance record rather than evidence of a long-running project that stopped.
The repository has no security policy, which weakens the documented process for reporting and handling vulnerabilities in a package intended for application integration.
All eight action references are unpinned, so workflow dependencies can drift; one workflow also grants top-level write access, a mild hygiene concern. The audit found no untrusted checkout, injection, or high-severity findings, which limits the risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
illuminate/cache Version ^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.