It has six years of releases, eight releases in the last year, current tests and release notes, and two active contributors within an organization-backed project. The missing security policy leaves less guidance for reporting problems.
84%
Total Score
100
100
67
The repository has no SECURITY policy, leaving reporting and disclosure expectations unclear; this is a transparency gap but not evidence of abandonment.
Both workflows were analyzed completely and have no untrusted checkouts or script injection, but all 10 action references are unpinned and the audit found a high-confidence unpinned container image in lint.yml.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.42|^12.0|^13.0 | — | — |
illuminate/database Version ^11.42|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.