Two active contributors and six recent commits show ongoing care, while the linked repository includes tests, releases, and a security policy. One high-confidence workflow audit finding warrants checking the Dependabot auto-merge condition.
84%
Total Score
75
100
100
The top contributor made 83% of recent commits, creating concentration risk, although a second contributor remains active.
All six workflows were analyzed and all 39 action references are pinned, but a high-confidence bot-conditions finding reports that the Dependabot auto-merge actor check may be spoofable; broad write permissions add minor context.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^13.0||^12.0||^11.0||^10.0||^9.0||^8.0||^7.0||^6.0||^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.