It has a clear MIT license, substantial documentation, repository tests, and an audited workflow with no dangerous findings. The all-unpinned actions and missing security policy leave modest transparency and build-hygiene gaps.
64%
Total Score
50
88
67
This is the package's first release, published 0 days ago, so there is no release track record to demonstrate sustained maintenance. Its complete initial artifact provides some compensating evidence, but not long-term confidence.
The repository shows 0 commits and 0 active maintainers in the last 3 months, but the package is only 0 days old. This limits evidence of ongoing maintenance rather than proving abandonment.
The repository has 1 star, 0 forks, and 0 watchers. For a package released 0 days ago this is mainly a lack of supporting adoption evidence, not a severe concern by itself.
No repository security policy was found, leaving disclosure and response expectations undocumented. This is a modest transparency gap for a package handling one-time authentication codes.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings, and it has no broad top-level write permission. Both action references are unpinned, which creates a build-hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^13.0 | — | — |
illuminate/console Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
illuminate/notifications Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.