The MIT license, README, changelog, and matching repository make the package straightforward to inspect. Composer tooling and Dependabot are present, but the single-maintainer project has no security policy.
40%
Total Score
0
79
75
The package has had no release in more than four years and none in the last 12 months, despite four total releases. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long release gap and suggesting maintenance has stopped.
The linked repository has no security policy, leaving no documented path for reporting vulnerabilities. This is a transparency and maintenance gap.
The assessed release is v0.0.4-alpha, and all recent releases are prereleases. That indicates the package has not reached a stable maturity level.
All 11 action references are unpinned, and the audit found high-confidence bot-condition and unpinned-container-image issues. The pull_request_target workflow has no untrusted checkout or script-injection finding, which limits the immediate severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^2.0 | — | — |
illuminate/contracts Version ^9.0 | — | — |
khaled.alshamaa/ar-php Version ^6.2 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.