This is my package data-common
48%
Total Score
unhealthy
Risky: no registry releases for over a year and a high-confidence workflow issue weaken confidence in this release.
The package has made 5 releases, but none in the last 12 months after its latest release on 2024-12-23, indicating a prolonged release gap for a relatively young package.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, a meaningful maintenance concern that is only partly offset by the more recent push date.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow; three workflows also grant top-level write permissions, although no untrusted checkout or script injection was found.
The registry namespace and repository owner are both joinapi, but the owner is a user account rather than an organization, so this provides limited backing evidence.
There were no new or closed issues or pull requests in the last month, and 4 pull requests remain open, suggesting limited recent follow-through.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^v11.0.0 | — | — |
illuminate/contracts Version ^v11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.