The package has clear licensing, documentation, repository tests, and release notes, with a small runtime dependency set. Its workflow configuration needs tightening before relying on automated publishing and maintenance processes.
62%
Total Score
75
100
88
50
The package has 19 releases since July 2024, but none in the last 12 months despite a median interval of about 2 days. That sharply lowers confidence in continued maintenance.
There were zero commits and zero active maintainers in the last three months. Combined with no registry releases in the last year, this is meaningful evidence of currently inactive development.
The repository has no security policy. That is a transparency gap for reporting and handling vulnerabilities, though it does not by itself make the package unfit.
Version v0.0.19 is not a stable major release, although it is not marked as a prerelease and recent releases have not used prerelease versions. The 0.x version still signals an immature compatibility promise.
All 19 action references are unpinned, five workflows grant top-level write access, and the audit found high-confidence bot-condition, unpinned-image, and template-injection issues. No untrusted checkout or script-injection trigger was found, so these are workflow hygiene and supply-chain cautions rather than standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.