The repository has no commits in the past three months, although its recent release cadence and organization backing reduce abandonment concerns. CI also contains high-confidence template-injection warnings, unpinned references, and one failed audit file.
68%
Total Score
88
100
89
83
There were no commits and no active maintainers in the past three months. The 10 releases in the past 12 months partly compensate, but the recent source inactivity still raises maintenance concern.
The repository has no stars or forks and only two watchers. This is weak supporting evidence, but popularity is not decisive where release and ownership signals are available.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
All three workflows use unpinned references, one has an unpinned container image, and the release workflow has two high-confidence template-injection findings. One file also failed auditing, so the workflow review is incomplete; these are hygiene and supply-chain concerns, not proof of compromise.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
astrogoat/blog Version ^1.29 | — | — |
astrogoat/strata Version ^0.11.0 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.