Licensing, repository tests, dependency scanning, and a security policy improve day-to-day confidence. The workflow audit flags a high-confidence template-injection issue in the changelog workflow. The project is young and has a small contributor base, so long-term continuity is less proven.
76%
Total Score
67
94
100
The repository and registry are owned by the same individual, so the package identity is consistent, but there is no organizational backing shown to offset the small maintainer base.
The package is only 91 days old with three releases, all published within roughly one day, so its long-term maintenance record is still limited despite recent activity.
Two contributors are active, but the leading contributor made about 69% of recent commits, leaving maintenance somewhat concentrated for a user-owned project.
All four workflows were analyzed, all 15 action references are pinned, and no untrusted checkout or broad top-level write permission was found. However, the audit reports a high-confidence template-injection finding in update-changelog.yml, which is a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.