The README, release notes, repository tests, and MIT licensing make integration and ownership clear. However, the long release interval, no commits in the last three months, absent security scanning, and unpinned workflow actions warrant pinning this version and monitoring maintenance.
67%
Total Score
50
80
50
The package has five releases over about 3 years and 9 months, with one release in the last 12 months and a median interval of about 362 days. The recent 1.5.0 release shows it is not abandoned, but maintenance is infrequent.
The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the repository was pushed when version 1.5.0 was released.
Composer build tooling is present, but no security scanning tools were detected. That reduces transparency around ongoing security checks without indicating that the package is unsafe.
The repository has no documented security policy. This weakens the project's process transparency, though it is a documentation gap rather than evidence of abandonment.
All four workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 11 action references are unpinned, leaving workflow dependencies less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/scout Version ^10.0 | ^11.0 | — | — |
spatie/laravel-enum Version ^3.0 | ^4.0 | — | — |
illuminate/contracts Version ^10.0 | ^11.0 | ^12.0 | ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.