MIT licensing, tests, release notes, and organization-backed ownership provide useful transparency. Pin this version and watch for renewed releases or CI fixes before adopting it in a long-lived Laravel application.
62%
Total Score
75
100
94
67
The package has 11 releases since July 2024, but none in the last 12 months; the latest registry release was about 15 months ago. This is a meaningful maintenance concern despite the earlier regular cadence.
The repository had zero commits and zero active maintainers in the last three months. This weakens confidence in ongoing maintenance, especially alongside the absence of registry releases in the last 12 months.
The repository has no SECURITY.md or other security policy. This is a transparency gap for reporting and handling defects, though it is not evidence that the package is unsafe.
All 12 analyzed action references are unpinned, and the audit found high-confidence bot-condition and unpinned-container-image findings. Top-level write permissions also appear in three workflows; with no untrusted checkout or script-injection findings, this is a material CI hygiene concern rather than a standalone critical risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cslant/blog-core Version dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.