The project has a clear README, release notes, repository tests, and automated dependency scanning. Recent work is limited and concentrated in one contributor, so tighten the workflows before relying on it for a critical application.
62%
Total Score
67
94
50
One contributor made all 2 commits in the last 3 months. Organization ownership provides some handoff capacity, but no second active contributor is evidenced in this period.
The repository recorded only 2 commits in the last 3 months, showing limited recent maintenance activity. The repository was pushed recently, so this is slowing activity rather than clear abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. This is a transparency gap, though it is not evidence of a security defect.
Version v0.7.0 is not a stable major release, but it is not marked as a prerelease and recent releases have not been prereleases. Expect some API evolution because the major version remains 0.
The audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow, while the pull-request trigger has no untrusted checkout or script-injection sink. All 12 action references are unpinned, and three workflows grant top-level write permissions, creating meaningful maintenance and supply-chain hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
honed/core Version ^0.53.0 | — | — |
honed/option Version ^0.1.0 | — | — |
illuminate/support Version ^11.0||^12.0 | — | — |
illuminate/contracts Version ^11.0||^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.