The workflows leave container images unpinned, creating avoidable build-integrity risk. Clear documentation, tests, licensing, and release notes make adoption easier, but ongoing upkeep should be verified before a long-term commitment.
68%
Total Score
75
88
100
The package has 10 releases over roughly four years, but none in the last 12 months; this indicates a meaningful maintenance slowdown for a framework integration.
There were no commits and no active maintainers in the last three months, which is a concrete warning about current maintenance capacity despite the recent release.
Composer build tooling is present, but no security-scanning tool was detected; this is a hygiene gap rather than evidence that the release is unsafe.
All three workflows were analyzed with no untrusted checkouts or script injection, but both high-confidence findings concern unpinned container images and all five action references are unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
laravel/framework Version ^11.0|^12.0 | — | — |
always-open/laravel-process-stamps Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.