The package includes tests, a clear README, a matching repository, and release notes for this version. Recent repository commits are absent, and all six workflow actions are unpinned; the missing security policy adds a smaller transparency gap.
70%
Total Score
50
100
94
67
The repository is owned by an individual account rather than an organization, so the project appears to rely on an individual maintainer rather than formal organizational backing.
The repository recorded zero commits and zero active maintainers in the last three months. The same-day release partly offsets this because publication activity is recent, but the short-term development lull remains a maintenance concern.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, but it is not evidence that the package is unsafe.
Version 0.11.1 is not a prerelease, but the package remains below a stable 1.0 major version, so API stability may be less established.
All three workflows were analyzed with no audit findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all six action references are unpinned, leaving workflow dependencies exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-medialibrary Version ^8.0|^9.0|^10.0|^11.0 | — | — |
cviebrock/eloquent-sluggable Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.