Documentation, licensing, repository tests, and a security policy provide a solid starting point. The workflow passes its audit but inherits secrets and uses an unpinned action, so keep deployment permissions tightly scoped.
68%
Total Score
50
100
93
100
The package was published today and has only one release, so there is no release history to demonstrate sustained maintenance or compatibility over time.
There were no commits or active maintainers in the last three months; because the project was published today, this is limited evidence rather than proof of abandonment, but it leaves maintenance capacity unproven.
The single workflow was fully analyzed with no high-severity findings or untrusted checkouts, but it inherits secrets and its only action is unpinned; both are meaningful workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
setasign/fpdf Version ^1.8.6 | — | — |
setasign/fpdi Version ^2.6 | — | — |
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.