The repository has tests, release notes, licensing, and organization backing. Maintenance is unproven after one release, while workflow permissions and action pinning need tighter controls.
58%
Total Score
83
100
88
50
This is a young package with one release over 163 days and no established release cadence, so long-term maintenance remains unproven.
There were zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a package only 163 days old.
The repository is active rather than archived, but its last push was on the release date, so this does not demonstrate continuing maintenance.
No security policy is present, leaving vulnerability-reporting expectations unclear; this is a minor transparency gap rather than evidence of abandonment.
All 12 action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow; top-level write permissions across three workflows add avoidable exposure, though no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yethee/tiktoken Version ^0.11.1 || ^1.1 | — | — |
illuminate/console Version ^9.52.16 || ^10.28.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^9.52.16 || ^10.28.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.