Usable with caveats: it has a clear license, strong release documentation, tests in the repository, and a steady release history. However, no commits or active maintainers were recorded in the last three months, and the repository has workflow-permission and security-policy gaps.
68%
Total Score
50
100
100
60
One workflow uses pull_request_target, which can require careful review because it runs with elevated event context; no untrusted checkout or script-injection findings were detected.
The package uses post-autoload-dump and post-update-cmd scripts. These add install-time behavior that deserves review, although the signal does not establish that the scripts are unsafe.
Only one registry account, Chris Mellor, has publish access. This is a real continuity risk for an individually owned project, despite the package's otherwise active release history.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so there is limited visible institutional backing.
No commits and no active maintainers were recorded during the last three months, which conflicts with the recent release cadence and raises a maintenance-continuity concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.0 | — | — |
hosmelq/sse-saloon Version ^0.1.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.