Its tests, release notes, and recent release activity support continued maintenance. A single maintainer and four unpinned workflow actions leave continuity and build-integrity gaps, while licensing and dependencies are straightforward.
78%
Total Score
83
100
100
50
All one recent commit came from a single contributor, leaving maintenance concentrated in one person. The matching repository and package ownership provide continuity, but no alternate active contributor is evidenced.
No SECURITY.md or equivalent security policy was found. This is a transparency gap for reporting vulnerabilities, though it does not by itself indicate that the package is unsafe to depend on.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all four referenced actions are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 || ^14.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 || ^14.0 | — | — |
illuminate/validation Version ^11.0 || ^12.0 || ^13.0 || ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.