A security policy, repository tests, changelog, and MIT license provide useful project hygiene. The workflow audit also finds a high-confidence condition flaw and all 14 actions are unpinned.
15%
Total Score
0
64
100
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption and continuity risk for a dependency.
The repository recorded zero commits and zero active maintainers over the last three months. This indicates no current development capacity, although the archive status already carries the greater risk.
The linked repository is archived, despite a recorded push on March 19, 2026. Archived status strongly limits expected maintenance and makes future fixes or compatibility work uncertain.
The package has had seven releases since October 2023 but none in the 12 months before collection. This supports a substantial maintenance concern alongside the abandoned status.
All 14 analyzed action references are unpinned, and the audit reports a high-confidence bot-conditions finding in the Dependabot auto-merge workflow. These create avoidable build and automation risks, though they are secondary to the package's maintenance state.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.10.1 | — | — |
spatie/laravel-data Version ^4.13.1 | — | — |
illuminate/contracts Version ^12.0 | — | — |
saloonphp/cache-plugin Version ^3.0 | — | — |
saloonphp/laravel-plugin Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.