The repository has no commits in the last three months, and its workflows leave all 12 actions unpinned. It has a clear MIT license, release notes, and a matching repository, but workflow permissions and automation checks need care.
58%
Total Score
75
93
50
A post-autoload-dump install-time script runs during Composer installation. This adds execution surface and deserves review, although the signal does not show that the script is malicious or unusually risky.
The package has 30 releases, but none in the last 12 months and the latest registry release was nearly two years ago, which raises maintenance and abandonment concerns.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the absence of recent registry releases and indicating limited current maintenance.
The repository has no published security policy. This is a transparency and reporting gap, though it is a secondary concern for an otherwise identified and licensed project.
All 12 analyzed action references are unpinned, and three workflows grant top-level write permissions. The high-confidence bot-condition finding also indicates a potentially spoofable actor check; no untrusted checkout or script-injection sink was found, so this is workflow hygiene risk rather than a severe standalone issue.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.15 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
spatie/laravel-fractal Version ^6.0 | — | — |
kanekescom/laravel-helperia Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.