The release cadence is steady, with two active contributors and ongoing repository security checks. Keep the workflow permissions issue in your deployment review.
79%
Total Score
100
100
100
The audit analyzed all 7 workflows, but all 17 action references are unpinned, which weakens build reproducibility. It also found a high-confidence bot-conditions issue in a pull_request_target workflow that has top-level write permissions, making workflow review a genuine caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.11.4 | — | — |
saloonphp/saloon Version ^4.0 | — | — |
guzzlehttp/guzzle Version ^7.11.1 | — | — |
illuminate/support Version ^13.0 | — | — |
spatie/laravel-data Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.