The workflow uses three unpinned actions, although its permissions are read-only and the audit found no active issues. There is no security policy, and the repository has not yet established a maintenance record.
65%
Total Score
75
88
50
This is the first release, published today, so there is no release track record or established cadence yet. That is expected for a new package but leaves maturity unproven.
The repository has no commits from active maintainers in the last three months, but the package is only hours old, so this reflects limited history rather than confirmed abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a package used in application observability.
All three referenced actions are unpinned, which weakens build reproducibility and supply-chain hygiene. The workflow uses read-only permissions, has no untrusted checkout or injection findings, and completed fully.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/queue Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/console Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.