The repository includes tests, release notes, Dependabot, and a security policy, while the package keeps runtime dependencies small. GitHub Actions still has high-confidence template-injection findings and broad release permissions.
66%
Total Score
50
100
88
88
The repository is owned by a user account rather than an organization, so the single-maintainer and concentrated-contributor signals are not offset by visible organizational backing.
The package is only 48 days old with three releases, all within the last 12 months. The short history limits evidence of long-term maintenance despite the initially active cadence.
One contributor made all eight recent commits, leaving no demonstrated contributor redundancy and increasing continuity risk for this user-owned project.
The repository recorded eight commits in the last three months, showing recent activity, but all activity comes from one maintainer.
Version v0.2.1 is a stable release rather than a prerelease, but it remains below 1.0, so its API and maintenance direction are less established.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.