The package is well documented and backed by an active organization. Maintenance is thin recently, with one commit from one contributor in three months, and its workflow leaves all 11 actions unpinned; no security policy adds a smaller transparency gap.
72%
Total Score
67
100
100
83
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown in this period.
Only 1 commit was recorded in the last 3 months, from 1 active maintainer. The recent release is reassuring, but the low current activity leaves some maintenance risk.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is not evidence of unsafe code by itself.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, and it does not grant top-level write access. However, all 11 action references are unpinned, which weakens build reproducibility and action supply-chain controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version 12.*|13.* | — | — |
illuminate/view Version 12.*|13.* | — | — |
illuminate/config Version 12.*|13.* | — | — |
illuminate/session Version 12.*|13.* | — | — |
illuminate/support Version 12.*|13.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.