A single contributor carries all recent commits, and the workflows use unpinned actions with one high-confidence bot-condition finding. Licensing, tests, documentation, and organization backing are solid.
58%
Total Score
83
92
50
Packagist marks the package abandoned and points to elegantly/laravel-forex as the replacement. The active repository and current release activity reduce the abandonment concern, but the registry status still lowers confidence in adopting this package name.
One contributor made 100% of the 7 commits during the last 3 months. Organization ownership provides some handoff capacity, but the observed contributor concentration remains a maintenance risk.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, although active tooling and repository maintenance provide some compensating evidence.
All 8 analyzed action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.0||^4.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
saloonphp/cache-plugin Version ^3.0 | — | — |
elegantly/laravel-money Version ^4.0.0 | — | — |
saloonphp/laravel-plugin Version ^3.0||^4.0||^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.