The package has a clear README, MIT licensing, repository tests, and a release for this version. Its single-user project has been inactive since 2024, lacks a security policy, and contains a high-confidence unpinned container image in CI.
55%
Total Score
50
92
67
There have been no releases in the last 12 months, and the latest release was published more than three years ago. The 15-release history shows prior development but does not offset the current inactivity.
The repository recorded zero commits and zero active maintainers in the last three months. This is strong evidence of limited current maintenance capacity.
There were no new or closed issues or pull requests in the last month, while 9 issues and 2 pull requests remain open. This suggests unresolved maintenance demand.
The linked repository has no security policy. For a library that may handle application cart data, this reduces transparency around vulnerability reporting.
Both workflows were analyzed completely and avoid untrusted triggers and script injection, but all four action references are unpinned and the audit found a high-confidence, high-severity unpinned container image. This leaves CI exposed to changing external build inputs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0|^9.0|^8.0|^7.0|^6.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.