The project is about four months old, and all three recent commits come from one contributor. It includes tests, a substantial README, a license, and security scanning, but its workflow dependencies are not pinned.
62%
Total Score
50
93
50
This is a young package, about four months old, with only one release and no established release interval. That limits evidence of maturity and sustained maintenance.
One contributor made all three commits in the last three months. With a user-owned repository rather than organization backing, this creates a meaningful continuity risk.
There were three commits in the last three months, showing some recent activity, but the volume is modest for a package intended for production authorization use.
The repository has no security policy. For an authorization package, that reduces transparency about how security issues should be reported and handled.
The single workflow was fully analyzed with no reported audit findings or untrusted execution paths. However, all four action references are unpinned, leaving routine build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/auth Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/cache Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.