It has clear documentation, tests, a license, and a recent release. The organization-owned repository and security policy help, but maintenance is currently concentrated and workflow references are not pinned.
72%
Total Score
63
100
100
75
Only one registry account has publish access. The organization-backed repository provides context for this publishing arrangement, so this is a minor concern rather than evidence of project abandonment.
All one recent commit came from a single contributor. Organization backing offers some continuity, but no second active contributor is shown to provide a handoff path.
Only one commit was recorded in the last three months, indicating limited recent development activity despite the recent package release.
Both workflows were analyzed successfully with no untrusted checkout or script-injection trigger, but all 3 action references are unpinned and one high-confidence template-injection finding was reported; template injection alone is workflow hygiene, while the unpinned references add caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/log Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/config Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/filesystem Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.