The beta has no production track record yet, and all nine workflow actions are unpinned. Documentation, tests in the repository, licensing, and read-only workflow permissions provide useful safeguards, but maintenance history is still too short to establish long-term reliability.
67%
Total Score
50
75
50
The package is newly published, with two releases on the same day and no meaningful release history yet. The repository was also pushed today, so this shows limited history rather than abandonment.
There were zero commits and zero active maintainers in the preceding three months, but the package and repository are newly created, which limits how strongly this indicates stalled maintenance.
The repository has no security policy, which leaves no documented process for reporting and handling vulnerabilities. This is a transparency gap, though it is not evidence of a vulnerability by itself.
This is a prerelease beta, and all recent releases are prereleases, so the API and stored cache format may still change. That is a genuine adoption concern for production consumers.
Both workflows use read-only permissions and have no untrusted checkout or script-injection findings, but all 9 of 9 action references are unpinned, leaving build inputs less reproducible and harder to control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^12.0 || ^13.0 | — | — |
illuminate/console Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.