Recent commits from two contributors, tests, release notes, and security tooling show an active project with useful maintenance practices. The workflow audit found a high-confidence template-injection issue that should be fixed before relying on its automation.
72%
Total Score
83
100
94
75
The registry and repository are owned by the same individual, so package ownership is transparent, but there is no organization backing shown to provide maintenance handoff.
The package is only 93 days old and has three releases, all within that period, so its long-term maintenance record is still limited. Recent repository activity partly offsets the short history.
All four workflows were analyzed and all 15 action references are pinned, with no untrusted checkout or script-injection findings. However, a high-confidence template-injection finding in update-changelog.yml is a real workflow hygiene concern, even though no dangerous trigger or token overpermission was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.