A clear README, MIT licensing, and release notes make adoption easier. Unpinned workflow actions and no security policy leave minor process gaps.
76%
Total Score
100
93
50
The package is only 60 days old, with seven releases clustered around its first two days, so long-term maintenance cannot yet be established. Recent repository activity partly offsets that uncertainty.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a minor transparency gap rather than evidence of unsafe code.
All four analyzed action references are unpinned, which weakens reproducibility, but the single workflow has no untrusted checkout, script injection, or high-confidence audit findings and the audit completed fully.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
a2zwebltd/brandgeo-laravel-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.