The README, changelog, repository tests, and MIT licensing support straightforward adoption. Single-person ownership and the missing security policy leave less evidence of sustained stewardship.
63%
Total Score
50
90
50
Only one registry account has publish access, which limits publishing redundancy. The repository is owned by the same individual and recent release activity provides some compensating evidence.
The package is about two years old but has only three releases, with one release in the last year and a median interval of about 298 days. The recent release prevents this from indicating abandonment, but the cadence is slow.
The repository recorded no commits and no active maintainers in the last three months. The package was released recently, which partly offsets the concern but does not show ongoing maintenance.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. The package remains small and the repository includes tests, but that does not replace a documented security process.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned. That leaves avoidable build-integrity risk despite otherwise clean workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ~9.0|~10.0|~11.0|~12.0|~13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.