The project has a long release history, current stable version, tests, and a recent release. Maintenance is concentrated in one contributor, with no security policy and unpinned workflow actions adding smaller concerns.
72%
Total Score
50
100
50
All two recent commits came from one contributor, leaving maintenance dependent on a single active person; the repository is user-owned, so no organizational handoff evidence compensates for this concentration.
The repository had two commits in the last 3 months, showing recent maintenance, though activity is limited.
The repository has no security policy, reducing transparency about how vulnerability reports should be handled.
The single workflow was fully analyzed with no audit findings or untrusted-trigger sinks, but both action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/console Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/filesystem Version ~5.8.0|^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.