Tests, a changelog, security tooling, and organization backing provide solid project transparency. Recent inactivity and workflow weaknesses make this release worth pinning rather than tracking loosely.
68%
Total Score
75
100
100
75
The repository recorded zero commits and zero active maintainers in the last 3 months, indicating a recent pause in development despite the newer release history.
There are no new or closed issues in the last month and no merged pull requests, although two pull requests remain open; this supports the recent inactivity concern.
All 17 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow; the pull_request_target trigger has no reported untrusted checkout or script-injection sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.8 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/contracts Version ^13.0 | — | — |
cloudinary/cloudinary_php Version ^3.1 | — | — |
spatie/laravel-package-tools Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.