The repository has had no commits in the last three months, and its only release is about ten months old. Automated workflows also use unpinned actions and contain a high-confidence bot-condition warning, despite having tests, documentation, and Dependabot.
58%
Total Score
50
100
93
50
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has slowed for a young package.
All 12 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. There are no untrusted checkouts or script injections, but the workflow setup still needs hardening.
The package uses a post-autoload-dump install-time script. This is worth awareness during installation, but the signal alone does not show an unsafe or excessive lifecycle action.
This is a young package with one release, first published about ten months ago, so there is little release history to establish long-term maintenance.
There are no new issues or merged pull requests in the last month, although two pull requests remain open; this provides limited evidence of active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dallgoot/yaml Version ^1.0 | — | — |
stancl/tenancy Version dev-master | — | — |
illuminate/contracts Version ^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.