Documentation is clear, and the organization has two active contributors. The only notable concern is a high-confidence archived-action finding in its pull-request workflow; no untrusted checkout or script injection was detected.
82%
Total Score
100
100
83
The only workflow uses an archived action with high-confidence medium severity, and it also grants top-level write permissions. However, the audit found no untrusted checkout or script injection, so this is a contained hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
fapost/foundation Version ^0.2 || ^0.3 | — | — |
illuminate/support Version ^11.0 || ^12.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.