The repository includes tests, a changelog, MIT licensing, and Dependabot security tooling. Its workflows use all 12 actions without pinning and include a high-confidence bot-condition finding, while the single-maintainer project shows no recent commit activity.
52%
Total Score
50
94
Only one registry account has publish access, and project_backing identifies an individual-owned repository rather than an organization. This leaves a thin publishing and continuity base.
The package has had only two releases, both around August 2025, with no releases in the last 12 months despite being 387 days old. This indicates limited ongoing release maintenance.
The repository recorded zero commits and zero active maintainers during the last 3 months. The repository is not archived, but this recent inactivity raises maintenance and abandonment concerns.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0 | — | — |
laravel/cashier-paddle Version ^2.6 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.