The package has clear documentation, tests, a changelog, regular releases, and security scanning. Maintenance remains concentrated in one contributor despite organizational ownership.
62%
Total Score
67
100
83
The audit found a high-confidence template-injection finding in a pull_request_target workflow that also performs an untrusted checkout, creating a meaningful workflow supply-chain risk. All 16 action references are unpinned and all three workflows grant top-level write permissions, adding reproducibility and permission concerns.
One contributor made all six commits in the last three months, giving the project a single-person active bus factor. Organizational ownership provides some handoff capacity but no second recently active contributor is shown.
Six commits were made in the last three months, showing recent activity, but all came from one active maintainer. The activity is current but concentrated.
The repository has no security policy. This is a transparency and incident-reporting gap, although the reported automated security scanning partly offsets the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version ^11.0 || ^12.0 || ^13.0 | — | — |
vectorface/mysqlite Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.