The release includes a README, tests in the repository, release notes, and recent development with two active contributors. Organization backing and security scanning provide useful maintenance support, though workflow and licensing details deserve attention before adoption.
70%
Total Score
100
100
89
67
The artifact declares a proprietary license while its LICENSE.md is detected as Unlicense; although a license is present, the mismatch creates legal clarity risk.
A post-autoload-dump install lifecycle script is used. This is normal Composer behavior but means installation executes package-defined code.
The repository has one star and one fork, indicating limited external adoption. Popularity is only supporting evidence, so this modestly reduces maturity confidence without outweighing active maintenance.
The repository has no published security policy, leaving reporting and response expectations unclear for a package that handles deployment and infrastructure information.
All six workflows were analyzed, but all 15 action references are unpinned, three workflows grant top-level write access, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no reported untrusted checkout or script injection, so this is a hygiene and workflow-risk concern rather than a severe standalone verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.92 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.