The package has a clear README, license, release notes, repository tests, and organizational ownership. Its small dependency set and lack of install scripts reduce adoption friction, while pinning the workflow container would improve build reproducibility.
62%
Total Score
75
100
88
100
The package has seven releases over about two years, but none in the last 12 months; this indicates a meaningful maintenance slowdown despite a previously regular cadence.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the concern raised by the lack of registry releases in the past year.
Composer build tooling is present, but no security-scanning tools were detected; this is a minor transparency and maintenance gap rather than a severe risk.
All three workflows use unpinned references, and the audit found a high-confidence unpinned container image; one workflow file also failed analysis, so build reproducibility and audit coverage are limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
astrogoat/strata Version ^0.7.7|^0.8.0|^0.9.0|^0.10.0|^0.11.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.