Its documentation is unusually thorough, the repository is active, and it includes tests. The project is young and lacks a security policy, so maintenance transparency remains limited.
68%
Total Score
83
86
50
Two commits from two active maintainers in the last three months show some ongoing work, though the small volume limits evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving supply-chain hygiene less visible.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package that processes application data.
The assessed version is a stable major release and is not a prerelease, but 7 of the 9 recent releases were prereleases, which adds some maturity uncertainty.
The audit found one high-confidence medium-severity use of an archived action, and all four action references are unpinned. No dangerous triggers, untrusted checkouts, or script injections were detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version * | — | — |
overtrue/http Version ^1.2 | — | — |
psr/container Version ^1.0 || ^2.0 | — | — |
illuminate/queue Version ^10.0|^11.0|^12.0 | — | — |
illuminate/redis Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.