The package has a clear README, release notes, repository tests, and Psalm scanning. However, its last release and repository push were in February 2022, and all workflow image references are unpinned, so future compatibility and build reproducibility are concerns.
58%
Total Score
75
100
92
100
The latest release was in February 2022, with no releases in the last 12 months despite the package being about five years old. This indicates a substantial maintenance gap, though the package is not registry-deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no updates since February 2022. The repository is not archived, which provides only limited compensation.
All 12 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in php-cs-fixer.yml. No untrusted checkout, script injection, or broad top-level write permission was observed, so this is a hygiene and reproducibility concern rather than a severe dependency verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^8.73 || ^9.0 | — | — |
spatie/laravel-package-tools Version ^1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.