The project is small, has no security policy, and its CI uses an unpinned container image. Its repository still includes tests, and the release is clearly licensed.
60%
Total Score
50
88
50
The package has five releases since October 2021, but none in the last 12 months; the latest release was about 21 months ago. This indicates slowed maintenance, though the release intervals were previously fairly regular.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current development activity. The repository is not archived, but recent inactivity still raises abandonment risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, although the package is small and otherwise has visible source and tests.
Both workflows were analyzed successfully and have no untrusted checkouts or script injection, but one high-confidence finding reports an unpinned container image. Four of five action references are also unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.3 | — | — |
illuminate/config Version ^8.0||^9.0||^10.0||^11.0 | — | — |
illuminate/support Version ^8.0||^9.0||^10.0||^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.