The package is clearly identified, licensed, documented, tested in its repository, and backed by an organization. Its recent maintenance record is thin, and most workflow actions are unpinned, so pinning this exact version is prudent.
62%
Total Score
75
100
88
50
The package has 95 releases, but all 95 were published within the last 12 months and the median interval is 0 days, indicating a concentrated burst rather than demonstrated release maturity.
The repository recorded 0 commits and 0 active maintainers over the last 3 months. The package is not archived, but this provides little evidence of ongoing maintenance after its initial release burst.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself indicate abandonment.
The audit covered all 5 workflows with no reported high- or medium-severity findings and no untrusted checkouts or script injection. However, 13 of 14 action references are unpinned, and 2 workflows grant top-level write permissions, creating avoidable workflow supply-chain and permission risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^13 | — | — |
groupesti/laravel-datatables-html Version ^13 | — | — |
groupesti/laravel-datatables-oracle Version ^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.