Regular releases, a stable major version, and repository tests support continued maintenance. GitHub Actions uses nine unpinned references and has a high-confidence bot-condition finding, while no security policy is provided.
68%
Total Score
75
100
50
The repository has 8 open pull requests but no issues or pull requests were opened or merged in the last month. The regular release history partly offsets this otherwise limited recent collaboration activity.
No security policy was found in the repository. This is a modest transparency gap for a package that handles an external API, although security scanning is present.
All three workflows were analyzed, but all 9 action references are unpinned and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. A pull_request_target workflow also has top-level write permissions, though no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.10 | — | — |
spatie/array-to-xml Version ^3.2 | — | — |
spatie/laravel-data Version ^4.0 | — | — |
illuminate/contracts Version ^11.22|^12.0 | — | — |
saloonphp/cache-plugin Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.