Tests, a changelog, recent releases, and organizational ownership provide useful maintenance evidence. The missing security policy and workflow hygiene issues leave less transparency and automation safety than a mature project should have.
68%
Total Score
75
100
67
There were no commits and no active maintainers in the last three months. Although releases occurred during the last year, this recent lack of source activity is a maintenance caution.
No security policy is present in the repository. This is a transparency gap, though it is not evidence that the package is unsafe by itself.
All 9 analyzed action references are unpinned, and three workflows grant top-level write permissions; the audit also found one high-confidence bot-condition issue. The pull_request_target workflow has no untrusted checkout or script-injection finding, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabre/xml Version ^4.0 | — | — |
nesbot/carbon Version ^2.0|^3.0 | — | — |
ameax/xml-validator Version ^1.0 | — | — |
spatie/temporary-directory Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.