A single maintainer and only 10 stars limit the visible support base. Regular releases, a clear MIT license, and a matching repository help, but the workflow uses two unpinned actions.
68%
Total Score
50
100
75
Only one registry maintainer is listed, which creates a thin publishing and support base. The matching repository and recent releases provide some compensation but do not remove the continuity risk.
The repository is owned by an individual account rather than an organization, so there is no visible organizational backing to offset the single-maintainer base.
There were no commits and no active maintainers in the last three months. This weakens evidence of ongoing development despite the recent release history.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both referenced actions are unpinned, leaving the workflow exposed to changing action contents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
illuminate/pipeline Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.