Tests, release notes, and security scanning provide useful maintenance structure. However, the project reports no active development in the last three months, and its workflows use unpinned images and inherited secrets.
58%
Total Score
75
100
94
67
The package has existed since July 2020 with 19 releases, but only one release in the last 12 months, indicating a substantially slower recent cadence.
There were zero commits and zero active maintainers in the last three months, which is strong evidence of slowed maintenance and raises abandonment risk.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
All 12 action references are unpinned, and high-confidence findings identify unpinned container images in two workflows; a medium-confidence finding also reports inherited secrets in the changelog workflow. The audit was complete, with no untrusted checkouts or script injection detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
bavix/clickhouse-builder Version ^6.2 | — | — |
bavix/clickhouse-php-client Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.