The package includes tests, a README, and a clear MIT license. Its small project footprint and unpinned workflow dependency leave limited maintenance and build-reproducibility margin.
40%
Total Score
0
70
50
The latest release was nearly five years ago, with six releases concentrated in the first few days and none in the last 12 months. This strongly indicates the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the long release gap and increasing abandonment risk.
The repository has no security policy. For a small, stale package this reduces the transparency of vulnerability reporting, though it is secondary to the observed maintenance gap.
Version v0.1.5 is not a stable major release, so the API may still change; combined with the stale project, this makes adoption riskier than the version label alone suggests.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, its one action reference is unpinned, which weakens build reproducibility without creating a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.3 | — | — |
illuminate/contracts Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.