Its workflow uses unpinned actions, and the repository has no security policy. Clear documentation, tests, licensing, and organization backing provide useful safeguards despite the limited history.
62%
Total Score
75
100
83
75
The package is newly published, with one release in the last 12 months and no established release interval. That leaves maintenance and compatibility history unproven.
There were no commits or active maintainers during the measured three-month window, but the project is only hours old, so this is limited evidence rather than proof of abandonment.
The repository has no security policy. For a runtime package, that weakens transparency about vulnerability reporting and response.
Version v0.1.0 is not a stable major release, so its API and behavior may still change. There is no prerelease label to add further concern.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both of its action references are unpinned. The missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.