The repository includes tests, a changelog, clear documentation, and matching MIT licensing. It lacks a security policy, security scanning, and pinned workflow actions, which increases maintenance and build-integrity concerns.
58%
Total Score
75
86
50
The latest release was about 3 years ago, with no releases in the last 12 months. The package had a reasonable earlier cadence of 12 releases and a median interval of about 61 days, but current maintenance appears stalled.
There were no commits and no active maintainers in the last 3 months, consistent with the long gap since the last release and indicating a real abandonment concern.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe dependency risk by itself.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities in a package that handles external API requests.
The workflow audit completed cleanly with no untrusted checkouts, injection findings, or high-confidence audit issues. However, all 3 action references are unpinned, so the build remains exposed to changes in referenced actions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^8.0|^9.0|^10.0 | — | — |
guzzlehttp/guzzle Version ^7.0.1 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0 | — | — |
spatie/data-transfer-object Version ^3.0 | — | — |
spatie/laravel-queueable-action Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.