Usable with caveats: it is a well-documented, licensed package with tests, release notes, and active repository infrastructure. However, no commits were recorded in the last three months, and the project has workflow permission and security-policy gaps that merit review before adoption.
68%
Total Score
33
100
94
70
No commits and no active maintainers were recorded in the last three months, which is the strongest concern for ongoing maintenance and timely fixes.
One workflow uses pull_request_target for Dependabot auto-merge, but no untrusted checkout or script-injection patterns were detected; the constrained finding is a review item, not a severe workflow risk.
The package and repository are consistently owned by the same individual, providing clear ownership but no organizational backing or maintainer redundancy.
The package has existed since October 2020 with nine releases, but only one release in the last 12 months indicates a relatively slow cadence.
There are no open issues and two open pull requests, although no issues or pull requests were merged during the last month; this is a modest activity concern rather than evidence of abandonment alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/encryption Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.