The repository includes tests, a substantial README, and release notes for this version. The project has no security policy, and all four workflow actions are unpinned, leaving maintenance and build-integrity gaps despite organization backing.
62%
Total Score
75
75
50
The package is less than one day old, with eight releases and a median interval of about 36 minutes. That shows active initial publishing but provides no evidence of sustained maintenance yet.
The repository reports zero commits and zero active maintainers in the last three months, which is concerning for maintenance capacity. However, the repository is newly created and has eight merged pull requests in the last month, so this is not evidence of abandonment by itself.
The linked repository has no security policy. That reduces transparency for reporting and handling vulnerabilities in a package providing authentication, tenancy, and database functionality.
Version v0.1.7 is not a stable major release, so its API and behavior may still change substantially. It is not marked as a prerelease, which partly offsets that concern.
The single workflow was fully analyzed, scopes permissions at the job level, and has no untrusted checkout or injection findings. All four action references are unpinned, creating a modest build-integrity hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/bus Version ^13.0 | — | — |
illuminate/auth Version ^13.0 | — | — |
illuminate/http Version ^13.0 | — | — |
illuminate/queue Version ^13.0 | — | — |
illuminate/console Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.