Tests, a changelog, and a clear MIT license improve the package’s transparency. Its short history, single-contributor maintenance, and workflow hygiene leave limited evidence for long-term dependability.
62%
Total Score
67
92
75
The repository is owned by an individual user rather than an organization, so the single-contributor concentration has no visible organizational handoff to compensate for it.
The package is only 43 days old with three releases, all published within about six hours, so there is too little history to establish durable maintenance.
One contributor made all six commits in the last three months, leaving maintenance highly dependent on a single person.
The repository has no security policy, which reduces transparency about how vulnerabilities should be reported and handled.
The single workflow is fully analyzed and has no untrusted checkout or script-injection trigger, but all six action references are unpinned and two medium-confidence template-injection findings remain, creating workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=12.0 | — | — |
meilisearch/meilisearch-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.