Healthy and reasonable to adopt. It has sustained releases, active recent commits, tests, documentation, and a matching repository; the main caveats are heavy reliance on one contributor and incomplete workflow permission hardening.
88%
Total Score
75
100
100
80
The repository is user-owned rather than organization-owned, so the concentrated recent contribution pattern carries more continuity risk than it would with clear organizational backing.
Two contributors were active, but one made 95% of the 20 recent commits. This creates a genuine continuity risk despite the second contributor remaining active.
The repository has no published security policy, leaving vulnerability-reporting guidance unclear. This is a transparency gap, but not evidence of abandonment.
Six workflows lack top-level token permissions and one declares top-level write access; although some jobs use job-level permissions, the repository could restrict automation privileges more consistently.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.