The package includes repository tests, release notes, a security policy, and no install-time scripts. Its GitHub workflow leaves both actions unpinned, and the project has too little release history to establish long-term maintenance.
68%
Total Score
75
100
93
83
Only two releases were published on the same day, so there is not enough history to demonstrate sustained maintenance or release reliability.
No commits were recorded in the prior three months, but the package is only hours old and the repository was recently pushed, so this is primarily an absence of historical evidence rather than clear abandonment.
The workflow audit found no dangerous triggers, untrusted checkouts, injection issues, or audit findings, and it uses read-only permissions. Both of its action references are unpinned, creating a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
square/square Version ^45.0|^46.0|^47.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/view Version ^12.0|^13.0 | — | — |
illuminate/cache Version ^12.0|^13.0 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.