The package is documented, licensed, and backed by an organization, with recent releases and no deprecation or archive status. Maintenance has paused recently, while all six workflow actions are unpinned and no security scanning or policy is present.
64%
Total Score
75
100
88
75
The package has 51 releases over about five and a half years, but only two in the last 12 months, indicating a slower release pace rather than abandonment by itself.
There were no commits and no active maintainers during the last three months, which is a meaningful sign of slowed maintenance despite the recent release history.
Composer build tooling is present, but no security scanning tools were detected, leaving a maintenance and vulnerability-detection gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all six action references are unpinned, leaving workflow supply-chain versions less reproducible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0 | — | — |
asseco-voice/laravel-common Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.