The package is well documented, licensed, tested in its repository, and clearly linked to its source project. Its maintenance has gone quiet, and the workflow uses three unpinned actions, so pinning this release is preferable for a long-lived application.
64%
Total Score
50
88
50
The package has 24 releases since January 2019, but none in about 20 months and none in the last 12 months. That suggests maintenance may have slowed substantially despite a previously regular release cadence.
The repository recorded no commits and no active maintainers in the last 3 months. This is a meaningful sign of currently limited maintenance capacity, though the latest release includes release notes and the repository is not archived.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although the package has a public repository, tests, and a documented release process.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 3 action references are unpinned. That leaves avoidable build-reproducibility and action-change risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.0 | — | — |
spatie/valuestore Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.