The package has clear documentation, tests in its repository, an MIT license, and a security policy. Its single-maintainer project has gone without a registry release for about 19 months, while workflow permissions and action pinning need attention.
58%
Total Score
50
100
94
67
The package runs a post-autoload-dump install-time script, adding some installation complexity and execution surface even though no harmful behavior is shown here.
The package and repository are owned by the same individual account, providing direct ownership alignment but no organization-backed maintainer redundancy.
The package has 10 releases over about 35 months, but no release in the last 12 months and its latest release was about 19 months ago, which raises maintenance concerns.
The repository shows zero commits and zero active maintainers in the measured three-month window, weakening evidence of current maintenance capacity.
All 10 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a workflow-hygiene caution rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
aws/aws-sdk-php-laravel Version ^3.8 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.