The package includes tests, clear usage documentation, release notes, and a direct repository match. Its short release history, no commits in the last three months, missing security policy, and workflow script-injection and unpinned-action issues reduce confidence for long-term use.
60%
Total Score
50
100
88
50
The package is about 11 months old but has only two releases, both concentrated within roughly 3 hours. That provides limited evidence of an established maintenance pattern.
There were no commits and no active maintainers in the last three months. For a package released only about 11 months ago, this is weak evidence of ongoing maintenance.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The only workflow was fully analyzed and has one script-injection finding, four of four action references unpinned, and no top-level permissions block. No dangerous trigger or high-severity audit finding was reported, but the CI supply-chain hygiene is weak.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.00 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.