The package has a clear README, tests in the repository, a changelog, and an MIT license. Recent activity is quiet, and the workflows contain high-confidence bot-condition and unpinned-image findings that warrant review before adoption.
64%
Total Score
83
100
94
67
All five workflows were analyzed, but every action reference is unpinned and the audit found high-confidence bot-condition and unpinned-container-image issues. The pull_request_target workflow also has top-level write permissions, increasing the impact of workflow mistakes.
The project has existed since 2019 with 14 releases, but only one release in the last 12 months indicates a slower release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has recently slowed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version 13.*|12.*|11.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.