The project includes tests, release notes, a license, and active commits from two contributors. One high-confidence template-injection finding in the changelog workflow warrants review before automated releases.
80%
Total Score
100
100
94
100
The package is young at 49 days old and has only two releases, so long-term maintenance maturity is not yet established; recent repository activity partly offsets this limitation.
All four workflows were analyzed, all 12 action references are pinned, and no untrusted checkout or script-injection path was found. However, the audit found one high-confidence template-injection issue in update-changelog.yml, which is a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-sitemap Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.