The package is small and clearly documented, with repository tests, a changelog, and an MIT license. Its automated workflows also contain a high-confidence bot-condition issue and broad unpinned action use, increasing maintenance and build-trust concerns.
42%
Total Score
33
100
79
50
The package has had no releases in the past 12 months despite being about 639 days old; all six releases were concentrated near its December 2024 launch. This is strong evidence of stalled maintenance.
The repository recorded zero commits and zero active maintainers during the past three months. This is a direct abandonment concern for a package that may need compatibility updates.
All five workflows were analyzed, but all 12 action references are unpinned and three workflows grant top-level write permissions. More seriously, the auditor found a high-confidence bot-condition issue in the Dependabot auto-merge workflow; no untrusted checkout or script injection was detected.
The package and repository are owned by the same individual account, providing clear ownership but no organizational backing. This makes the zero-maintainer recent activity more consequential.
There has been no new or closed issue or pull request activity in the past month, while one issue and four pull requests remain open. Together with zero recent commits, this suggests limited ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.