Regular releases, tests, a changelog, and a matching MIT license support ongoing use. Maintenance is concentrated in one contributor, so ownership continuity remains a concern.
67%
Total Score
50
100
100
83
The repository is owned by the same individual account that publishes the package, so the single-person maintenance concentration is not offset by organization backing.
One contributor made all recent commits, leaving maintenance dependent on a single active person and increasing continuity risk.
Only two commits were recorded in the last three months, so current maintenance activity is modest despite the recent release.
The audit found a high-confidence, high-severity bot-condition issue in the Dependabot auto-merge workflow. All nine action references are unpinned, and a test workflow installs a package outside its lockfile, adding workflow supply-chain hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/pipeline Version ^1.0 | — | — |
spatie/browsershot Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.