It has a clear MIT license, tests, release notes, and a matching repository, with no install-time scripts. The small maintainer base, absent recent commits, and workflow audit issues leave meaningful maintenance and automation concerns.
58%
Total Score
63
100
94
75
Only one registry account has publish access. For this individually owned project, that represents a real bus-factor concern, though the repository's tests and documentation provide some supporting project structure.
The repository is owned by an individual account rather than an organization, so the single registry maintainer does not have visible organizational backing to compensate for the thin maintainer base.
The package has 15 releases since April 2020, but its latest registry release was in July 2023 and it had no releases in the following 12 months. This is a meaningful sign of slowed maintenance for a dependency that may need framework or API updates.
There were no commits and no active maintainers in the three months measured. Combined with the old latest registry release, this raises abandonment and compatibility risk.
The repository has no security policy. That is a transparency gap for reporting and handling vulnerabilities, although it is not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^9.0 | ^10.0 | — | — |
james.xue/ali-safe-api Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.