Unpinned GitHub Actions and no security policy reduce transparency. The repository includes tests and release notes, and the package is licensed.
68%
Total Score
50
100
100
50
The package and repository are owned by the same individual account, so there is no organization backing to offset the narrow maintainer base.
One contributor made 100% of the 3-month commit activity. This concentration leaves maintenance dependent on a single active contributor.
Only 1 commit was recorded in the last 3 months, indicating limited recent development activity even though the repository was pushed recently.
The repository has no SECURITY.md or other declared security policy. That weakens vulnerability-reporting transparency for a package used in application builds.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or write-wide permissions, but all 3 action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.0 | — | — |
livewire/livewire Version ^3.3 || ^4.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.