Clear licensing, repository alignment, and release notes support transparency. The small release history, no commits in three months, missing security policy, and weak workflow pinning reduce confidence in long-term maintenance.
58%
Total Score
50
100
88
50
Only two releases have been published, both on the same day, leaving limited evidence of an established release track despite the package being about 190 days old.
There were zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a package that may need updates with its ecosystem.
Composer is used for builds, but no security-scanning tooling is reported, leaving a modest transparency and hygiene gap.
The repository has no security policy, so its process for receiving and handling vulnerability reports is not documented.
All nine analyzed action references are unpinned, weakening build reproducibility. Two workflows grant top-level write permissions, but there are no untrusted checkouts, injection findings, or high-confidence audit findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
blade-ui-kit/blade-icons Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.