The repository had no commits in the last 3 months and the release stream has been quiet for about 13 months. The project is backed by an organization, includes repository tests and a security policy, but its workflow audit found a high-confidence unpinned container image.
62%
Total Score
83
100
81
83
The package has 11 releases over about 3 years, but none in the last 12 months; the last release was about 13 months ago. This indicates materially slowed maintenance, despite a historically regular median interval of about 45 days.
There were no commits and no active maintainers in the last 3 months. That is a concrete sign of currently inactive development and increases the risk that issues or compatibility needs will remain unaddressed.
The repository has no stars or forks and only four watchers. Popularity is supporting evidence rather than a verdict, but these low counts provide little external evidence of maturity.
Composer is used for the build, but no security scanning tools were detected. The missing scanning is a hygiene gap, partly offset by the repository's security policy and workflow checks.
Both workflows were analyzed and no untrusted checkout or script injection was found, but the audit identified a high-confidence unpinned container image and both action references were unpinned. One file failed analysis, so the audit is not fully complete.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
astrogoat/strata Version ^0.7.0|^0.8.0|^0.9.0|^0.10.0|^0.11.0 | — | — |
illuminate/contracts Version ^8.37 || ^9.9|^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.