Clear licensing, extensive documentation, release notes, and a matching repository support adoption. The automated workflows have broad permissions, unpinned actions, and one high-confidence bot-condition finding, so updates and publishing deserve extra scrutiny.
55%
Total Score
75
93
The package has 21 releases since September 2023, but none in the last 12 months and the latest release was over two years ago. This materially increases abandonment and compatibility risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided activity signal compensates for this slowdown.
All 14 action references are unpinned, three workflows grant top-level write permissions, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull request target trigger has no untrusted checkout or script-injection sink, limiting the impact to caution rather than danger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
kanekescom/laravel-helperia Version ^2.0 | — | — |
kanekescom/laravel-siasn-api Version ^2.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.