The repository includes tests, a changelog, and a security policy. Seven releases in 12 months show an initially active project, but no commits in the last three months and eight unpinned workflow actions add maintenance and build-integrity risk.
61%
Total Score
50
88
75
The repository had zero commits and zero active maintainers in the last three months. The earlier release cadence provides some compensation, but the current maintenance gap lowers confidence in ongoing support.
The repository has one star, zero forks, and one watcher, indicating limited visible adoption. Popularity is only supporting evidence, so this modestly reduces confidence rather than determining the verdict.
The repository uses build tooling, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all eight action references are unpinned, leaving build inputs less reproducible and more exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cline/morphism Version ^2.0.1 | — | — |
laravel/framework Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
cline/variable-keys Version ^2.0.1 | — | — |
facade/ignition-contracts Version ^1.0.2 | — | — |
spatie/laravel-package-tools Version ^1.93.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.