The package has a clear MIT license, a substantial README, repository tests, and no install-time scripts. Its workflow references are all unpinned, adding avoidable build-integrity risk.
58%
Total Score
50
92
75
The package is about 1 year 8 months old, has only 3 releases, and had no releases in the last 12 months. This suggests maintenance has stalled despite a healthy initial release sequence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the absence of recent registry releases and increasing abandonment risk.
The repository has no published security policy. This is a transparency and vulnerability-reporting gap, though it is less concerning than the inactive maintenance signals.
The single analyzed workflow has no high- or medium-confidence findings and no unsafe triggers or untrusted checkout, but all 3 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
laravel/framework Version ^7.0 || ^8.0 || ^9.0 || ^10.0 || ^11.0 | — | — |
ehsandevs/bresources Version ^1.5 || ^2.2 || ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.