It has had no release since July 2020 and no recent commits, although the README, tests, license, and static analysis provide useful project context. Pinning a different maintained package would be safer.
8%
Total Score
0
50
50
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on the release.
Only two releases exist, both from July 2020, and there have been no releases in the last 12 months. This strongly supports the abandonment concern despite the package having an identifiable release history.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with its archived status, this shows no current maintenance capacity.
The linked repository is archived and was last pushed in January 2022, indicating the source is no longer maintained. The repository does match the package and mentions it, so this is not a linkage concern but remains a severe abandonment risk.
All eight analyzed action references are unpinned, and a high-confidence audit found an unpinned container image. This is a workflow hygiene weakness, though it is secondary to the package's abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^1.2 | — | — |
illuminate/filesystem Version ^7.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.