The repository includes tests and the package has a clear MIT license. Its workflow leaves all six actions unpinned, and no security policy or automated scanning is present. Pin this version if adopting it despite the maintenance gap.
58%
Total Score
50
83
50
One registry maintainer is publishing the package. The linked repository is user-owned rather than organization-backed, so there is limited visible publishing capacity to offset that narrow base.
All three releases arrived within minutes on the same day, with no later releases over the following 227 days. This shows an initial burst but little evidence of sustained release maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful abandonment concern for a package released 227 days ago.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not by itself evidence that the package is unsafe.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all six action references are unpinned. That leaves routine build inputs exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.