The release is licensed and includes tests, a changelog, and release notes. Its workflow uses four unpinned actions, while security scanning and a security policy are absent.
61%
Total Score
50
83
50
The package has 34 releases over about 8 years, but its latest release was in December 2024 and there were no releases in the following 12 months, which lowers confidence in active maintenance.
The repository recorded no commits and no active maintainers in the last 3 months. The repository was pushed in February 2025, so this indicates a recent maintenance pause rather than confirmed abandonment.
Composer is used for the build, but no security scanning tools are configured. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy. For a service client that handles authentication configuration, this leaves vulnerability-reporting expectations unclear.
All four analyzed action references are unpinned, reducing build reproducibility. The audit also reported a low-confidence cache-poisoning pattern; because confidence is low and no untrusted trigger or checkout was found, it is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0 | — | — |
cerpus/cerpushelper Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.