The small repository has had no commits in the last three months, and it lacks a security policy or scanning tools. Regular releases, an organization-backed repository, tests, clear licensing, and a matching source tree provide useful safeguards; workflow action pinning remains weak.
68%
Total Score
67
100
94
75
There were zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent push and continuing registry releases partly offset abandonment risk.
There are no new or closed issues in the last month and no merged pull requests, while three pull requests remain open; this supports the recent maintenance slowdown but is not severe on its own.
Composer build tooling is present, but no security scanning tools were detected. For a package handling uploaded attachments, that is a genuine repository hygiene gap.
The repository has no security policy. This weakens transparency for reporting and handling vulnerabilities, though it does not by itself show that the release is unsafe.
Both workflows were analyzed without high-confidence findings, dangerous triggers, or untrusted checkouts, and neither grants top-level write access. However, all 6 action references are unpinned, leaving a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0 | — | — |
maennchen/zipstream-php Version ^3.1 | — | — |
asseco-voice/laravel-common Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.