The package has clear documentation, tests, a changelog, MIT licensing, and no install-time scripts. Its workflows contain a high-confidence unpinned container image, adding a modest maintenance and build-hygiene concern.
58%
Total Score
67
100
88
100
A single individual has registry publish access, leaving limited publishing redundancy; for this individually owned project, that is a modest resilience concern rather than a severe risk.
The package has only three releases and none in the last 12 months; its latest registry release was about three years ago, which raises abandonment risk.
There were no commits and no active maintainers in the last three months, indicating that development activity has currently stalled despite the more recent repository push.
Composer is used for builds, but no security scanning tool was detected; the repository's security policy provides some compensating transparency.
Both workflows were fully analyzed with no untrusted checkouts or script injection, but all four action references are unpinned and the audit found a high-confidence unpinned container image, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/cache Version ^8.0|^9.0|^10.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0 | — | — |
illuminate/database Version ^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.