This is a generally usable and reasonably mature release: it has existed for about 3 years 7 months, has 16 releases including 4 in the last 12 months, uses a stable non-prerelease version, is not deprecated or archived, and has a matching repository with substantial test coverage and CI tooling visible in the source tree. The main concern is that repository activity reports no commits and no active maintainers in the last 3 months, despite the latest release being published recently, which weakens evidence of ongoing hands-on maintenance. Security transparency is also limited by the lack of a security policy and security scanning, while workflow permission and untrusted-checkout findings warrant review, but these do not by themselves make the package unfit to depend on.
74%
Total Score
63
100
89
70
Two workflows were analyzed and none use pull_request_target or script injection, but one workflow uses an untrusted checkout pattern, so its automation should be reviewed before treating the CI setup as fully hardened.
Only one registry account has publish access, which is a modest publishing continuity concern, although the repository is owned by an organization and the release history shows continued publishing.
The repository reports 0 commits and 0 active maintainers in the last 3 months, which is the clearest maintenance concern and conflicts with the recent registry release and recent repository push.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is neutral to mildly limited evidence because the absence of backlog does not establish active maintenance.
The repository has zero stars and forks and one watcher. This provides little external validation, but popularity is supporting evidence rather than a health verdict for a package with other maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.