The package is well documented and tested, with a matching repository, MIT license, and security policy. Its small maintainer base, quiet recent commits, and high-confidence workflow findings make long-term upkeep less certain.
63%
Total Score
50
100
94
100
One registry maintainer creates a narrow publishing bus factor. The linked repository and recent release evidence provide some compensation, but not enough to remove the maintenance concern.
The package is mature at about four years old, but only one release was published in the last 12 months, indicating a slower recent cadence despite a history of 10 releases.
The repository recorded 0 commits and 0 active maintainers in the last three months. This is a meaningful sign of currently quiet development, though the repository is not archived and a recent release exists.
All 11 action references are unpinned, and the audit found high-confidence bot-condition and unpinned-container-image issues. The pull_request_target workflow has no untrusted checkout or script injection, so these are workflow hygiene risks rather than a severe release-blocking issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
abordage/html-min Version ^1.0 | — | — |
illuminate/support Version ^8.0 || ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.