Recent work includes three releases in the last year, release notes, tests, and a current repository. One contributor, no security policy, and unpinned workflow actions leave maintenance and build-trust gaps; choose a maintained alternative if available.
44%
Total Score
50
86
75
Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a serious adoption warning even though the assessed release is recent.
One contributor made all commits in the last three months, leaving no demonstrated handoff capacity for this user-owned project.
Only one commit was made in the last three months by one active maintainer. Recent activity exists, but the very low cadence provides limited evidence of sustained maintenance.
The repository has no security policy. For a password-auditing package, this weakens vulnerability-reporting transparency.
The workflow audit was complete, uses read-only permissions, and found no high-confidence dangerous findings. However, both action references are unpinned, leaving a build reproducibility and action-tampering hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/async Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.