Security transparency is limited, and the build workflow leaves action references unpinned. Recent registry releases and a matching, unarchived repository provide useful maintenance evidence, but recent repository activity is quiet.
68%
Total Score
75
94
50
The package defines a post-update command, adding install or update-time behavior that consumers should understand. This is a modest supply-chain and maintenance consideration, not a severe risk by itself.
The repository recorded no commits and no active maintainers in the last three months. Although releases remain regular, the absence of recent development activity is a meaningful maintenance caution.
Composer build tooling is present, but no security scanning tools were detected. That limits automated security hygiene and lowers transparency somewhat.
The repository has no security policy. This does not show a vulnerability, but it leaves disclosure and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned. The clean audit offsets some concern, while unpinned dependencies remain a workflow hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/view Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
bjuppa/metatagbag Version ^1.0 || ^2.0 | — | — |
league/commonmark Version ^1.3 || ^2.0 | — | — |
illuminate/routing Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.