The repository is actively changing, has two equally active contributors, and publishes release notes. It lacks security scanning and pins none of its three workflow actions, so maintenance controls remain a concern.
82%
Total Score
100
100
94
50
A post-install command runs during installation, adding execution-time behavior beyond ordinary dependency loading. The provided signal does not show that it is unsafe, so this is a modest transparency concern.
Composer build tooling is present, but no security-scanning tool was detected. This leaves an avoidable verification gap for a package handling installation and application code.
The repository has no security policy, reducing transparency about how users should report vulnerabilities and receive fixes.
Both workflows were analyzed successfully and use read-only permissions with no detected dangerous sinks or audit findings. However, all three action references are unpinned, leaving workflow behavior exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cms-orbit/core Version ^4.6 | — | — |
laravel/framework Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.