The package has a clear MIT license, documentation, repository tests, and dependency scanning. Its very small adoption and workflow weaknesses provide limited reassurance for a long-lived dependency.
38%
Total Score
0
79
50
The last release was nearly four years ago, with no releases in the last 12 months. This is strong evidence of abandonment despite four releases shortly after the package launched.
The repository recorded zero commits and zero active maintainers in the last three months, confirming that development has stopped rather than merely slowing.
The repository has only 2 stars, 1 fork, and 1 watcher. Low popularity is not decisive, but it provides little outside evidence of sustained use or review.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The README mentions a policy but the collected repository evidence shows none exists.
All 12 action references are unpinned, and a high-confidence audit finding reports spoofable actor checks in a Dependabot auto-merge workflow. The pull_request_target trigger is ordinary by itself, but these weaknesses reduce release-process confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^2.15 | — | — |
illuminate/contracts Version ^9.0 | — | — |
beyondcode/laravel-comments Version ^1.3.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.