Tests, release notes, and security scanning provide solid project discipline. All recent commits come from one contributor, and the workflows leave all 15 actions unpinned, including a high-confidence unpinned container image finding. Depend on it with workflow and maintenance risk in mind.
72%
Total Score
67
100
93
67
The registry and repository are owned by the same individual account, so the single-maintainer concentration is not offset by organizational backing.
One contributor made all six commits in the last three months, leaving no demonstrated handoff capacity and increasing abandonment risk if that maintainer becomes unavailable.
The repository has no security policy, a transparency gap for a package that performs dependency upgrades, though automated security scanning partly compensates.
Version 0.4.1 is not a stable-major release, but it is a normal release rather than a prerelease and recent releases contain no prereleases.
All 15 action references are unpinned, and a high-confidence audit found an unpinned container image; the separate low-confidence cache-poisoning finding is only a hygiene concern. Three workflows also grant top-level write permissions, without untrusted checkout or script-injection paths.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version 0.3.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.