MIT licensing, a complete README, repository tests, release notes, and a security policy make the project transparent for adopters. Its compact dependency set and lack of install-time scripts reduce integration and installation risk.
58%
Total Score
75
100
80
100
The package has 29 releases over roughly four years, but none in the last 12 months despite a historical median interval of about 20 days, indicating a substantial slowdown.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release slowdown and increasing abandonment risk.
Composer build tooling is present, but no security-scanning tools were detected, leaving a project-level hygiene gap alongside the workflow concerns.
All five analyzed action references are unpinned, and the audit found one high-confidence, high-severity unpinned container image; one workflow file also failed analysis, so workflow hygiene is incomplete.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
astrogoat/strata Version ^0.11.0 | — | — |
illuminate/contracts Version ^8.37 || ^9.0|^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.