The repository has tests, a changelog, a matching README, and a clear MIT license. Its maintenance record is thin, and the workflow uses an unpinned container image, so future support and build reproducibility remain concerns.
52%
Total Score
50
50
83
83
This is the only release, published nearly five years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance.
The package declares eight runtime dependencies, including integrations for crawling, calendars, and Laravel. This is a meaningful dependency surface but is consistent with the package's stated functionality.
The repository and registry are tied to the same individual owner. This is transparent, but it also indicates a single-person project rather than organization-backed maintenance.
The repository recorded no commits and no active maintainers in the last three months. Although it was pushed in January 2024, current maintenance capacity appears limited.
The single analyzed workflow is complete and has no untrusted checkouts or injection findings, but both action references are unpinned and the audit found a high-confidence unpinned container image.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fabpot/goutte Version ^4.0 | — | — |
google/apiclient Version ^2.0 | — | — |
html2text/html2text Version ^4.3 | — | — |
illuminate/contracts Version ^8.37 | — | — |
spatie/icalendar-generator Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.