It includes a working test suite, release notes for v1.1, and a matching repository, which improve transparency. Its small audience and single-person ownership leave limited evidence of support if problems emerge. The workflow also uses two unpinned actions.
47%
Total Score
25
63
50
The package has only two releases, both in September 2022, and none in the last 12 months; the latest release is nearly four years old. This is strong evidence of abandonment risk despite the stable version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. There is no provided evidence of ongoing maintenance.
Only one registry publishing account is listed, limiting observable publishing capacity. The matching repository and user-owned project provide some continuity, but not meaningful redundancy.
The repository has 0 stars, 0 forks, and 1 watcher, so there is little community evidence to offset the lack of recent maintenance. Popularity is supporting evidence rather than a verdict on its own.
The single workflow was fully analyzed with no injection or high-severity findings, but both referenced actions are unpinned. That is a reproducibility and supply-chain hygiene concern, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0|^6.0 | — | — |
phpstan/phpstan Version ^1.0 | — | — |
illuminate/support Version ^7.0|^8.0|^9.0 | — | — |
illuminate/database Version ^7.0|^8.40|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.