The package has a clear README, release notes, tests, and a matching source repository. Its workflows use broad permissions, leave all 12 actions unpinned, and contain a high-confidence bot-condition warning.
52%
Total Score
0
100
86
50
Only two releases were published, both in April 2023, with no release in more than three years. This is substantial evidence of abandonment risk despite the stable version format.
The repository recorded no commits and had no active maintainers in the last three months, consistent with the long release gap and indicating limited ongoing maintenance.
No security policy is present in the repository. This is a minor transparency gap, but it is not enough to outweigh the broader maintenance evidence on its own.
All 12 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was detected, so this is a caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.