Healthy and reasonable to depend on. It has active recent releases, a maintained repository with tests, documentation, security tooling, and no deprecation, but ongoing work is concentrated in one contributor and some workflows use broad write permissions.
84%
Total Score
60
100
100
67
One of four workflows uses pull_request_target, which warrants care because that trigger can expose privileged workflow context to pull requests. No untrusted checkout or script-injection patterns were detected, limiting the concern.
Only one registry account has publish access. This is not a health verdict by itself, but it leaves publishing continuity dependent on a single person.
The registry namespace and repository are owned by the same individual, confirming a directly backed project. Because the owner type is a user rather than an organization, continuity remains dependent on that maintainer.
One contributor made all 7 commits in the last 3 months, creating a real continuity risk. The linked repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset this concentration.
The repository received 7 commits in the last 3 months, showing recent work, but all activity came from one active maintainer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^13.0||^12.0||^11.0||^10.0||^9.0||^8.0||^7.0||^6.0||^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.