The package is licensed, documented, tested, and supported by a matching organization-owned repository. Its build uses security scanning and has no install-time scripts, but workflow references are unpinned.
68%
Total Score
75
100
94
67
The project has existed for about 9 years with 22 releases, but only 1 release in the last 12 months; the recent v0.6.1 release and release notes provide some evidence of ongoing maintenance.
All recent commits came from one contributor, creating concentration risk. Organization ownership provides some handoff capacity, so this is a caution rather than a severe risk.
Only 1 commit was recorded in the last 3 months, indicating limited recent activity; the recent release and push provide partial compensation but not a strong maintenance cadence.
The repository has no published security policy, reducing transparency about vulnerability reporting and response expectations.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 4 action references are unpinned, which is a supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lampager/lampager Version ^0.5 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 || ^14.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 || ^13.0 || ^14.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.