Documentation, tests, release notes, and a clear MIT license provide a solid foundation. The five workflow actions are unpinned, and the project has no published security policy, leaving avoidable maintenance and build-hygiene gaps.
65%
Total Score
50
83
50
The package is only 119 days old and has three releases, all published on the same day with intervals of about 1 hour 22 minutes. This shows initial activity but provides little evidence of sustained release cadence.
The repository recorded zero commits and zero active maintainers during the last three months. Given the package's young age, this is not proof of abandonment, but it is a meaningful sign that ongoing maintenance is unconfirmed.
No repository security policy was found. That reduces transparency around vulnerability reporting, although the package's tests, documentation, and security scanning provide some compensating project hygiene.
Version v0.2.0 is not on a stable major version, so its API may still change. It is not marked as a prerelease, which partly offsets the concern for consumers expecting an early but published release.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all five referenced actions are unpinned, leaving build inputs less reproducible and exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.7 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.