Security scanning and release notes improve confidence, while the missing security policy leaves incident handling unclear. The single recent contributor and unpinned action references warrant extra caution for long-lived production use.
70%
Total Score
63
100
67
The repository is owned by a user rather than an organization, so the concentrated recent contributor activity represents a genuine single-owner continuity risk.
One contributor made all commits during the last three months, concentrating maintenance responsibility in a single person and increasing continuity risk for a user-owned project.
Only one commit was recorded in the last three months, which is thin activity for an actively maintained library, although recent merges and the current release provide compensating evidence.
No repository security policy was found, leaving vulnerability-reporting and response expectations unclear despite the presence of security scanning tools.
All 14 analyzed action references are unpinned, and one high-confidence medium-severity finding reports an archived action. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not independently dangerous.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.