Clear documentation, repository tests, and release notes make integration easier. The small dependency set and security policy add useful guardrails, but the project has little operating history.
68%
Total Score
67
100
86
83
One registry publishing account is consistent with the linked repository's user ownership, but it leaves little publishing redundancy for this young project.
The package is only 37 days old with two releases and a 38-day median interval, so its maintenance track record is still limited. Recent publication is reassuring but cannot establish long-term continuity.
All three recent commits come from one contributor, so maintenance depends entirely on that person. The linked repository is user-owned, with no organizational backing shown to compensate for the concentration.
The release is v0.1.1 rather than a stable major version, indicating an early API with greater potential for breaking changes. It is not marked prerelease, which partly offsets that concern.
All three workflows were analyzed with no dangerous sinks or audit findings, and none grants top-level write access. However, all six action references are unpinned, leaving avoidable supply-chain drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.