The small codebase has repository tests, a clear README, MIT licensing, and no install-time scripts. Workflow automation also has high-confidence bot-condition and unpinned-image findings, so its maintenance hygiene is weak.
18%
Total Score
50
64
100
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on the release.
The linked repository is archived, and its last push was about 13 months ago. Archiving strongly indicates that ongoing maintenance should not be expected.
The package has eight releases over about four years, but none in the last 12 months; the latest release was about 18 months ago. This supports the abandonment concern.
The repository recorded no commits and no active maintainers in the last three months. The archived state makes this inactivity more significant than a normal quiet period.
All 11 analyzed action references are unpinned, and the audit found high-confidence bot-condition and unpinned-image issues. The pull request target workflow also has top-level write permissions, making automation hygiene a meaningful concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^2.0|^3.0|^4.0 | — | — |
illuminate/cache Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.