The repository includes tests, a substantial README, Dependabot, and clear organization ownership. Confirm the package’s licensing before adoption because the declared and detected licenses disagree.
58%
Total Score
75
80
50
The artifact declares MIT and includes a license file, but the repository license file was detected as AGPL-3.0. This mismatch requires licensing review before dependency adoption.
The package has had no registry release in about 14 months, despite eight releases overall. This is a meaningful maintenance concern, although the repository was pushed more recently.
There were zero commits and zero active maintainers in the last 3 months, indicating currently inactive development. The recent repository push provides only limited compensation because it does not show ongoing commit activity.
All 12 analyzed action references are unpinned, and three workflows grant top-level write access. The audit also found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow; no untrusted checkout or script-injection sink was found, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^2.0|^3.0 | — | — |
illuminate/support Version ~10|~11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.