Documentation is extensive, and this version includes release notes plus repository tests and a changelog. The workflow audit found all action references unpinned and a low-confidence cache warning, while no security policy is published.
79%
Total Score
100
100
83
83
This is the first release and the package is 0 days old, so there is no track record yet to demonstrate long-term maintenance or compatibility.
The repository has no stars, forks, or watchers. As a newly released package this is weak supporting evidence, but it does not outweigh the observed maintenance activity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and assurance gap.
The repository has no published security policy, which makes vulnerability reporting and response expectations less clear for a package handling OAuth tokens.
All five workflows were analyzed without untrusted checkouts or injection findings, and permissions are scoped in some workflows. However, all 16 action references are unpinned, and the low-confidence cache-poisoning finding is a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
artisanpack-ui/core Version ^1.0 | — | — |
artisanpack-ui/hooks Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.