Organization backing, a matching repository, licensing, tests, and security tooling provide useful safeguards. The package also runs a post-autoload-dump script, while its workflows use broad permissions and unpinned actions.
62%
Total Score
75
86
67
The package runs a post-autoload-dump lifecycle script during Composer installation, adding executable install-time behavior that consumers should understand.
The package is about 812 days old but has only four releases and one release in the last 12 months, indicating a thin release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may currently be paused.
Version 0.3 is not a stable major release, so compatibility expectations are lower even though it is not marked as a prerelease.
All five workflows were analyzed, but all 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects Dependabot auto-merge. No untrusted checkout or script-injection sink was found, so this is a hygiene and workflow-control concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.0 | — | — |
filament/filament Version ^3.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.