The MIT license, repository tests, and matching package source improve transparency. Dependabot and Composer tooling are present, but adopting this release still carries substantial maintenance uncertainty.
42%
Total Score
0
79
This is the package's only release, published 1121 days ago, with no releases in the last 12 months. That strongly suggests the package is inactive and raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. There is no provided recent activity to offset this concern.
The latest and only version is v0.0.1-alpha, so it is explicitly pre-release and has no demonstrated stable release history. This increases compatibility and maturity risk.
All five workflows were analyzed, but all 12 action references are unpinned and the audit found a high-confidence bot-conditions issue; three workflows also grant top-level write permissions. These are meaningful workflow-hygiene concerns, though no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
filament/filament Version ^3.0-stable | — | — |
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.