The project has had no commits or releases for about 13 months, and its workflows use 7 unpinned actions or images. Clear documentation, tests, release notes, licensing, and a non-archived repository provide useful support.
62%
Total Score
50
100
88
67
The package has only 3 releases since April 2023 and none in the last 12 months, with releases typically about 14 months apart. This indicates slow maintenance, though the latest release is still relatively recent.
There were no commits and no active maintainers in the last 3 months, despite the repository being collected about 13 months after the latest release. This is a meaningful maintenance warning.
Composer is used for builds, but no security scanning tooling is reported. This is a transparency and maintenance-hygiene gap, not evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a modest transparency gap for a maintained library.
All 3 workflows were analyzed, but 7 of 10 action references are unpinned; the audit also found high-confidence template injection and an unpinned container image. The pull_request_target trigger has no untrusted checkout or script-injection sink, so these remain hygiene concerns rather than standalone severe risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phar-io/version Version ^3.2 | — | — |
illuminate/support Version ^10.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.