Clear documentation and a small dependency surface make the package straightforward to evaluate. Confidence is limited by its single maintainer, absent recent commit activity, and lack of security scanning.
64%
Total Score
50
100
83
83
Only one registry maintainer, Jerome, is listed. The linked project is user-owned rather than organization-backed, so there is little visible publishing redundancy.
The package has 19 releases over 552 days, but only 2 releases in the last 12 months. The latest release is current, partly offsetting the otherwise modest recent cadence.
The repository recorded zero commits and zero active maintainers during the last 3 months. Although the release was recently pushed, the observed development activity is too thin to demonstrate sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no security policy. For a package that calls GitHub APIs and handles configuration tokens, this leaves vulnerability reporting expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
symfony/process Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
illuminate/support Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.