Documentation, licensing, and a recent release make integration straightforward. Keep the workflow configuration under review before granting it access to sensitive build or release environments.
72%
Total Score
100
100
100
50
A post-autoload-dump install-time script is present. This adds execution during installation and deserves attention, although the signal does not show harmful behavior by itself.
The repository has no security policy. That is a transparency gap for a package handling email tracking and webhooks, though active maintenance and Dependabot partly compensate.
All 12 action references are unpinned, and three workflows grant top-level write permissions. The audit also found one high-confidence bot-conditions issue in a pull_request_target workflow; no untrusted checkout or script injection was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | ^11.0 | ^12.0 | ^13.0 | — | — |
cleaniquecoders/traitify Version ^1.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.