Clear documentation, tests, licensing, and organization ownership support adoption. Pin v0.6.0 and plan an upgrade review if the project resumes or dependencies need security fixes.
58%
Total Score
75
83
75
The package has 26 releases but none in the last 12 months, with the latest release in April 2025. That weakens confidence in ongoing maintenance, despite a substantial release history.
There were zero commits and zero active maintainers in the past three months, consistent with the lack of releases and indicating a meaningful abandonment risk.
The repository has no security policy, leaving no documented reporting path for vulnerabilities. This is a transparency gap, partly offset by the package's tests and organization-owned repository.
v0.6.0 is not a stable major release, and 65% of recent releases were prereleases. Consumers should expect a less mature compatibility promise.
All three analyzed action references are unpinned, and the audit reported a low-confidence cache-poisoning pattern. The workflow has no untrusted checkout or script-injection path, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|| ^11.0 || ^12.0 | — | — |
jfcherng/php-diff Version ^6.15 | — | — |
illuminate/console Version ^10.0|| ^11.0 || ^12.0 | — | — |
illuminate/support Version ^10.0|| ^11.0 || ^12.0 | — | — |
illuminate/database Version ^10.0|| ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.