Tests, documentation, and a matching organization-owned repository provide useful support. The build workflow uses an unpinned container image, adding avoidable supply-chain hygiene risk.
42%
Total Score
50
75
50
The package has had only 3 releases, all clustered in January 2021, with no releases in the last 12 months despite being about 5 years and 8 months old. This is strong evidence of abandonment risk.
There were no commits and no active maintainers in the last 3 months, consistent with the package's prolonged lack of releases and materially increasing abandonment risk.
The repository has no security policy, reducing transparency for reporting vulnerabilities. This is a minor concern compared with the much longer maintenance gap.
v0.1.3 is not a prerelease, but it remains below 1.0, so compatibility expectations are weaker for a package that has not advanced since its initial release period.
Both workflows were analyzed completely and have no untrusted checkouts or script injection, but the audit found a high-confidence unpinned container image and all 5 action references are unpinned. This is a meaningful but secondary build-integrity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
akkurateio/laravel-core Version ^0.1 | — | — |
akkurateio/laravel-back-components Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.