The stable major version, MIT license, release notes, and repository tests provide a useful baseline. All workflow actions are unpinned, adding a smaller supply-chain hygiene concern.
15%
Total Score
0
57
75
Packagist marks the entire package as abandoned, with no replacement supplied. This is a severe maintenance and abandonment risk for a new dependency.
The latest release was in February 2022, with no releases in the last 12 months. The long release history shows maturity, but the roughly four-year release gap indicates abandonment risk.
The repository recorded no commits and no active maintainers in the last three months. Together with the archived status, this confirms that current maintenance capacity is absent.
The linked repository is archived, so active maintenance is not expected even though it was last pushed in May 2024. This strongly limits confidence in future fixes and compatibility work.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 11 action references are unpinned, which leaves avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^5.5 || ^6.0 || ^7.0 || ^8.0|| ^9.0 | — | — |
illuminate/events Version ^5.5 || ^6.0 || ^7.0 || ^8.0|| ^9.0 | — | — |
illuminate/support Version ^5.5 || ^6.0 || ^7.0 || ^8.0|| ^9.0 | — | — |
illuminate/container Version ^5.5 || ^6.0 || ^7.0 || ^8.0 || ^9.0 | — | — |
illuminate/contracts Version ^5.5 || ^6.0 || ^7.0 || ^8.0|| ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.