Three releases in about ten months and active tests provide useful project discipline. The single-contributor maintenance base and high-confidence workflow warning warrant extra care for a dependency still below 1.0.
62%
Total Score
88
100
88
50
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding reports spoofable actor context in the Dependabot auto-merge workflow. Three workflows also grant top-level write permissions, although no untrusted checkout or script-injection sink was found.
The package runs a post-autoload-dump install-time script, adding execution during installation and therefore modest supply-chain exposure.
All 3 recent commits came from one contributor, leaving maintenance highly concentrated and increasing abandonment or handoff risk.
The repository has 0 stars and 0 forks, offering little external validation; this is supporting evidence only and is partly expected for a young package.
No repository security policy was found, which is a transparency gap for reporting vulnerabilities, though it is not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
honed/core Version ^0.55.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.