The MIT license, tests, release notes, and recent repository work provide useful support. Treat the alpha-only release stream, concentrated contribution, and unpinned workflow actions as reasons to pin and test carefully.
72%
Total Score
83
94
50
The package runs a post-autoload-dump install-time script, which adds execution during installation and warrants attention, though this is common for framework packages.
One contributor made about 85% of recent commits, creating concentration risk; the organization-owned project provides some handoff capacity but does not remove the narrow active contributor base.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The assessed release is an alpha and all recent releases are prereleases, so the package may change incompatibly even though development is active.
All seven workflows were analyzed with no audit findings or untrusted-code sinks, but all 18 action references are unpinned and three workflows grant top-level write permissions; these are workflow hygiene concerns rather than severe risks here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mews/purifier Version ^3.4 | — | — |
craftile/laravel Version ^0.11.0 | — | — |
spatie/browsershot Version ^3.61||^5.0 | — | — |
symfony/filesystem Version ^6.4 || ^7.0 || ^8.0 | — | — |
bagistoplus/couleur Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.