The package is small and clearly documented, with repository tests, release notes, and ordinary dependencies. Recent maintenance is quiet, and the CI workflow uses unpinned references, including a high-confidence unpinned container image.
62%
Total Score
75
100
93
75
Only 3 releases have been published across about 21 months, with 1 release in the last 12 months. The recent 7.3.2 release provides some evidence of continued maintenance, but the overall cadence is sparse.
There were no commits and no active maintainers during the last 3 months. Although the release was published more recently, the lack of current commit activity weakens confidence in ongoing maintenance.
The repository has no security policy. This is a modest transparency gap for a package that is intended to be used in application dependencies.
All 8 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in the PHP CS Fixer workflow. The workflows were fully analyzed and have no untrusted checkouts or script-injection findings, so this is a caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.71|^3.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.