The repository is active but maintained by one contributor, and its five workflow actions are all unpinned. Move to the named replacement rather than taking a new dependency on this abandoned package.
38%
Total Score
75
80
67
Packagist marks the entire package abandoned and names fopost/social-laravel as the replacement. This is a direct adoption risk despite the linked repository remaining active.
One contributor made 100% of the last 3 months' commits. This leaves maintenance highly dependent on a single person, although the repository is organization-owned.
The repository has no security policy. That reduces disclosure transparency, though the package does provide tests, a changelog, and release notes.
Both workflows were analyzed with no reported audit findings or untrusted checkout paths, but all 5 action references are unpinned and one workflow grants top-level write permission. These are meaningful release-hygiene weaknesses without evidence of an active exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
owlstack/owlstack-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.