Slate 3.0.3 appears to be a healthy, actively maintained release with a long package history, 21 releases in the last 12 months, current repository activity, stable-major versioning, clear licensing, tests, documentation, changelog coverage, and a matching organization-owned repository. The main concerns are that all 29 recent commits came from one contributor and all three workflows lack top-level permission declarations; these are meaningful resilience and CI-hardening gaps, but they are partly offset by organization backing, active pull-request activity, Dependabot, a security policy, and the absence of dangerous workflow patterns. It is a reasonable dependency for developers who can tolerate a relatively concentrated maintainer base.
82%
Total Score
80
100
94
88
Recent activity is fully concentrated in one contributor, with a 100% top-contributor share and only one contributor in three months; organization backing mitigates handoff risk but does not eliminate dependence on one active maintainer.
There were 29 commits in the last three months, showing substantial recent activity, but all were produced by one active maintainer.
All three workflows lack top-level permission declarations. Although none grants top-level write access, explicitly declaring least-privilege permissions would provide stronger CI security hygiene.
Version 3.0.3 is a stable major release and is not a prerelease, although the recent prerelease share of 0.65 suggests some parallel experimentation and warrants modest caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.