Usable with caveats: the package is licensed, backed by a matching organization repository, and includes tests and release notes. However, it has had no further release or commit activity since May 2025, with no adoption signals and several workflow-security hygiene gaps.
62%
Total Score
75
100
78
63
One workflow uses pull_request_target, which can require careful handling of untrusted pull-request input. No untrusted checkouts or script-injection patterns were detected, limiting the concern.
This is the only release, published about 16 months ago, with no releases in the last 12 months. That limited history makes long-term maintenance uncertain.
There were no commits and no active maintainers in the last three months, consistent with the package having received no visible maintenance since its initial release.
The repository has zero stars, forks, and watchers. Popularity is not required for a healthy small package, but these counters provide no supporting evidence of community use or review.
The linked repository is not archived, but its last push was in May 2025, so the non-archived status does not compensate for the later lack of activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.275 | — | — |
illuminate/contracts Version ^9.0|^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.