Recent releases, tests, documentation, and security tooling provide meaningful maintenance evidence. The registry marks the package abandoned, recent repository commits are absent, and a workflow uses an unpinned container image.
42%
Total Score
75
100
88
100
Packagist marks the entire package as abandoned, with no distinct replacement identified; this is a substantial adoption and continuity risk despite other healthy project signals.
The repository recorded no commits and no active maintainers in the last three months, which conflicts with the recent release history and raises a maintenance-continuity concern.
All 3 workflows were analyzed without trigger or script-injection issues, but all 7 action references are unpinned and the audit found a high-confidence unpinned container image, leaving builds exposed to changing upstream content.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slickdeals/statsd Version ~3.0 | — | — |
jdorn/sql-formatter Version ^1.2 | — | — |
illuminate/contracts Version ^11.0|^12.0 | — | — |
league/flysystem-aws-s3-v3 Version ^3.29 | — | — |
spatie/laravel-package-tools Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.