It has a clear license, useful documentation, repository tests, and regular recent releases. Maintenance is concentrated in one contributor, while workflow hygiene needs attention because action references are unpinned and the audit found a high-confidence bot-condition issue.
65%
Total Score
83
94
50
All 6 recent commits came from one contributor, leaving maintenance and continuity dependent on a single active person.
The repository has no security policy, leaving users without a documented process for reporting and handling vulnerabilities.
Version 0.4.1 is not a stable major release, so compatibility expectations are lower than for a 1.x package, although it is not marked as a prerelease.
All 11 analyzed action references are unpinned, and a high-confidence bot-condition finding affects a workflow using pull_request_target; no untrusted checkout or script injection was found, limiting the risk to a material hygiene concern rather than a severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.0||^4.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
spatie/laravel-webhook-client Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.