The package has tests, release notes, a clear MIT license, and a security policy. Its workflow uses two unpinned actions, and no repository security scanning is reported.
73%
Total Score
83
100
86
83
All 11 recent commits came from one contributor, creating a real continuity concern. Organization ownership provides some backing, but no second active contributor is shown in this period.
Composer build tooling is present, but no security-scanning tool is reported. This is a modest transparency and hygiene gap rather than evidence of abandonment.
The assessed release is a release candidate rather than a stable major version, although the package also has a current stable release and only 20% recent prereleases.
The only workflow was fully analyzed with no injection or high-severity findings, but both action references are unpinned. The absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0 | — | — |
illuminate/view Version ^10.0 | — | — |
league/commonmark Version ^2.2 | — | — |
illuminate/support Version ^10.0 | — | — |
spatie/yaml-front-matter Version ^2.0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.