The package has a clear MIT license, useful documentation, repository tests, and no install-time scripts. Its workflow leaves both actions unpinned and lacks a security policy, while recent commit activity is absent despite a recent repository push.
58%
Total Score
50
100
88
67
The package has made no release in the last 12 months, and its latest release was about 3 years ago. This is a meaningful maintenance concern, although the repository is not archived.
There were zero commits and zero active maintainers in the last 3 months. This weakens confidence in ongoing maintenance, despite the repository's recent push timestamp.
Composer is used for the build, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The workflow audit completed successfully with no high-confidence findings or unsafe triggers, but both analyzed action references are unpinned. That leaves the build exposed to mutable action changes and is a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^7.0|^8.0|^9.0|^10.0 | — | — |
shivella/laravel-bitly Version ^1.1 | — | — |
spatie/laravel-settings Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.