It has a clear MIT license, a substantial README, repository tests, and no install-time scripts. The workflow uses four unpinned actions and has medium-confidence template-injection findings, while the new project has no follow-up commit activity yet.
68%
Total Score
50
88
67
This is the first release and the package is newly published, so there is no release track record yet to demonstrate sustained maintenance.
The repository shows zero commits and zero active maintainers in the last three months, although this overlaps with the package being newly released and therefore is not evidence of abandonment by itself.
The linked repository has no security policy, which is a modest transparency gap for a package with no other established security process shown.
All four referenced workflow actions are unpinned, and the audit reports two medium-confidence template-injection findings. There are no untrusted checkouts or script-injection findings, so this is workflow hygiene risk rather than a severe supply-chain issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version >=11.0 | — | — |
illuminate/support Version >=11.0 | — | — |
edulazaro/wiretables Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.