This is a usable but very new pre-1.0 package with several positive transparency and safety indicators: it is MIT licensed, not deprecated, backed by an active-looking organization-owned repository, includes repository tests, and uses read-only workflow permissions without the analyzed dangerous workflow patterns. However, the release history is only hours old with three releases, and repository activity currently shows no commits or active maintainers in the measured three-month window, so maintenance maturity is unproven. The artifact also omits a README and tests, though repository tests materially compensate for those packaging gaps. Dependence is reasonable for evaluation or controlled use, but the package warrants monitoring until it demonstrates sustained maintenance.
62%
Total Score
75
50
78
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pestphp/pest Version ^4.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/database Version ^13.0 | — | — |
pestphp/pest-plugin Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.