The single active contributor limits continuity, and the project has no published security policy. MIT licensing, tests, recent releases, and an organization-owned repository provide useful support.
62%
Total Score
83
100
92
67
All 7 commits in the last 3 months came from one contributor, giving the project a narrow maintenance base. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package intended for application integration.
Version v0.3.1 is not a stable major release, but it is not marked as a prerelease and recent releases have no prerelease share. The versioning signals caution for maturity but do not indicate an unstable build.
The audit found four high-confidence unsound-condition findings and two high-confidence ad-hoc package installs; 11 of 16 action references are unpinned. No untrusted checkout or script-injection path was found, so this is a hygiene concern rather than a severe supply-chain risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^9.0|^10.0|^11.0|^12.0 | — | — |
ssolweb/string-morpher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.