The repository includes tests, a matching README, and release notes for this version. Its small runtime dependency set and organization ownership are positives, while the missing security policy reduces transparency.
58%
Total Score
75
100
92
50
The package has only three releases, all published within about 20 hours, followed by roughly seven months without another release. That brief release burst provides limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the past three months. For a package less than a year old, that is a meaningful maintenance and abandonment concern.
The repository has no security policy, reducing transparency about vulnerability reporting and maintenance handling. This is a modest concern, not evidence that the package is unsafe.
All 11 analyzed GitHub Actions references are unpinned, so workflow builds can change when upstream action references change. The audit found no untrusted checkouts, script injection, or high-severity findings, which keeps this a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12 | — | — |
illuminate/contracts Version ^12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.