The package has clear documentation, an MIT license, matching source repository, and a read-only workflow. Its single-release history, no recent commits, tiny adoption, absent tests, and lack of a security policy reduce confidence in long-term maintenance.
55%
Total Score
50
83
50
This is the only release, published about 17 months ago, with no releases in the last 12 months. That makes ongoing maintenance uncertain for a package intended as a development dependency.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with a project that has gone quiet since its initial release.
The repository has only 2 stars, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of broad community support.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a maintenance and transparency gap, though not evidence of a vulnerability by itself.
The one workflow was fully analyzed and uses read-only permissions with no audited injection or secret findings. However, both of its action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^7.0 || ^8.0 || ^9.0 || ^10.0 | — | — |
nette/php-generator Version ^3.5 | — | — |
nwidart/laravel-modules Version ^8.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.