The repository has no commits in three months, and the project has only two releases created minutes apart. All workflow actions are unpinned and a high-confidence bot-condition issue remains, although the MIT license, matching repository, release notes, and Dependabot improve transparency.
56%
Total Score
50
100
93
50
The package has only two releases, both published within minutes on the same day, which shows limited release maturity. The repository was pushed more recently, but the release track record remains thin.
The repository recorded zero commits and zero active maintainers during the last three months, indicating that maintenance has currently gone quiet.
All seven action references are unpinned, and every workflow grants top-level write permissions. The audit also found a high-confidence bot-condition issue in the Dependabot auto-merge workflow; the pull_request_target trigger has no reported untrusted checkout or script-injection sink, so this is a caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.47.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.