The repository has no security policy, and its only workflow uses three unpinned actions with a script-injection pattern. Licensing, tests, documentation, and organization backing provide useful transparency.
67%
Total Score
75
83
50
The package has 13 releases over about 2 years and a release within the assessed period, but only 2 releases in the last 12 months indicate a slower recent cadence.
The repository recorded no commits and no active maintainers in the last three months, weakening evidence of ongoing maintenance despite the recent release.
Composer build tooling is present, but no security scanning tools were detected, leaving a project hygiene gap.
The repository has no published security policy, so there is no documented process for reporting or handling vulnerabilities.
The single workflow is fully analyzed and has no high-confidence audit findings, but all 3 action references are unpinned and the workflow contains one script-injection pattern, creating avoidable CI supply-chain and execution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
javaabu/helpers Version ^1.70 | — | — |
illuminate/support Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-activitylog Version ^4.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.