Usable with caveats: the package is clearly backed by a matching organization repository, has regular releases, documentation, tests in the repository, and security tooling. However, it is still early-stage at version 0.1.1, has had no commits in about 35 days, and its workflow permissions and missing security policy reduce confidence for long-term maintenance.
62%
Total Score
67
100
94
50
One workflow uses pull_request_target for Dependabot auto-merge, but no untrusted checkouts or script injection were detected; the remaining workflow risk is limited but warrants review.
There were zero commits and zero active maintainers in the last three months, which is a real maintenance concern for a young package, although the recent repository push and release history provide some compensating evidence.
The repository has one open issue and eight open pull requests, with none merged in the last month; this suggests outstanding work and limited recent follow-through.
No repository security policy was found, leaving vulnerability-reporting guidance undocumented for a package that handles cloud API authentication and access.
Three workflows declare top-level write permissions, two omit top-level permissions, and none declare read-only permissions; this is weaker workflow least-privilege hygiene than desirable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^4.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
saloonphp/cache-plugin Version ^3.0 | — | — |
saloonphp/laravel-plugin Version ^4.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.