The package has clear documentation, tests, a changelog, and organization backing. Its license, active release history, and security tooling add confidence, but workflow hygiene and concentrated ownership warrant attention.
67%
Total Score
83
100
63
The package runs a post-autoload-dump install-time script. This is a potentially relevant installation behavior, but the signal provides no evidence that it performs unsafe or unexpected actions.
One contributor made 100% of the 7 commits in the last 3 months. Organization backing partly offsets the handoff risk, but maintenance remains concentrated.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting guidance unclear.
All 4 workflows were analyzed, but all 8 action references are unpinned and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, and only one workflow grants top-level write access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.0||^4.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
saloonphp/cache-plugin Version ^3.0 | — | — |
elegantly/laravel-money Version ^4.0.0 | — | — |
saloonphp/laravel-plugin Version ^3.0||^4.0||^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.