A clear MIT license, repository tests, and release notes for this version improve confidence. The project has no security policy, recent commit activity is absent, and both workflow actions are unpinned.
67%
Total Score
50
92
50
No commits and no active maintainers were recorded in the last 3 months. Although the package has a recent release, the lack of recent source activity lowers confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected. This leaves a modest gap in the project's maintenance hygiene.
The repository has no security policy. This is a transparency and maintenance gap, though it is not by itself evidence that the release is unsafe.
The workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, and it scopes permissions at job level. However, both referenced actions are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kontenta/kontour Version ^2.0 | — | — |
bjuppa/laravel-blog Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.