Testing, documentation, licensing, and dependency hygiene are in place. Recent commit activity is absent, while workflow permissions and a high-confidence bot-condition issue add maintenance and automation concerns.
58%
Total Score
38
100
88
83
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has gone quiet after the initial release burst.
All 12 action references are unpinned, three workflows grant top-level write access, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The audit found no untrusted checkout or script-injection sink, which limits the severity.
One registry maintainer is consistent with the matching user-owned repository, but it leaves limited visible publishing redundancy if that maintainer becomes unavailable.
The registry namespace and repository owner match, but the project is user-owned rather than organization-backed, so there is no visible organizational continuity signal.
Eight releases in about 148 days, with a median interval of about 1 day, show active early development, though the short project history limits maturity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
firebase/php-jwt Version ^6.10 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.