Usable with caveats: this is a well-documented, licensed package with repository tests and matching source, but it is only hours old and has not yet demonstrated sustained maintenance. Review its install-time script and GitHub Actions permissions before adopting it broadly.
68%
Total Score
75
100
94
60
One of five workflows uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script-injection pattern was detected, but this workflow type warrants review because it can run with elevated repository context.
The package runs a post-autoload-dump install-time script. This is a meaningful execution point for consumers, although the signal does not show additional suspicious script behavior.
One registry maintainer is consistent with this user-owned project, but it also indicates a limited individual maintainer base if the project needs continuity.
The package is only about two hours old and has two releases, with a median interval of about 6.6 minutes. That is too little history to establish maintenance reliability, despite the recent activity.
The repository records zero commits and zero active maintainers over the last three months, but the package is only about two hours old, so this is an immature history rather than evidence of a collapsed project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grantholle/scru64 Version ^1.0 | — | — |
illuminate/database Version ^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.