The package has a clear README, repository tests, a changelog, and a security policy. Its workflows use an unpinned container image, adding avoidable build risk.
40%
Total Score
50
88
100
A single registry maintainer provides limited publishing redundancy, although the linked repository is clearly identified with matching package references.
Only two releases were published, both within about six days, and none in the last five years. This strongly suggests the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no release since June 2021.
Version 0.1.1 is not a stable-major release, which signals an early-stage API, but it is not marked as a prerelease.
All three workflows were analyzed and no untrusted checkout or script injection was found, but every seven action reference is unpinned and the audit found a high-confidence unpinned container image.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version >=8.0 | — | — |
illuminate/contracts Version >=8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.