Strong tests, documentation, and a clear package layout provide useful adoption support. Security scanning is absent, and workflow dependency pinning is incomplete, so maintenance and build hygiene remain modest concerns.
68%
Total Score
50
100
88
75
This is a young package with one release about 9 months ago and no subsequent releases. That is not abandonment by itself, but it leaves little evidence of sustained maintenance.
There were zero commits and zero active maintainers in the three months before collection. For a package with only one release, this leaves ongoing maintenance capacity unproven.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and upkeep gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented path for reporting vulnerabilities. This modestly reduces project transparency for a library handling business workflows.
The sole workflow was fully analyzed with no reported audit findings and no dangerous triggers or sinks. However, one of two action references is unpinned, leaving a small build-reproducibility gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.