Release documentation, tests, and licensing are in place, while the repository is not archived or deprecated. The project has no measured commit activity over three months, lacks a security policy, and leaves two of three workflow actions unpinned.
68%
Total Score
75
100
88
75
Only two releases exist and the package is less than one day old, so there is not enough release history to demonstrate sustained maintenance.
No commits or active maintainers were measured in the last three months, which weakens evidence of ongoing maintenance despite the recent push and merged pull requests.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users are given no documented reporting process for security issues.
The single workflow was fully analyzed with no audit findings or dangerous triggers, but two of its three action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.8|^4.0 | — | — |
laravel/framework Version ~11.0|~12.0|~13.0 | — | — |
openspout/openspout Version ^4.28 | — | — |
spatie/eloquent-sortable Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.