Usable with caveats: the package is licensed, documented, tested in its repository, and has a recent stable release. However, there have been no commits or active maintainers in the last three months, and the repository has workflow-permission and security-policy gaps.
68%
Total Score
67
100
94
63
One of six workflows uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can grant elevated workflow context, although no untrusted checkout or script injection was detected.
The project has existed since June 2022 and has eight releases, with the latest released in March 2026. The median interval of about 206 days and only one release in the last year indicate a slow but not abandoned release cadence.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although it is partly offset by the March 2026 release and June repository push.
There are no open issues and two open pull requests, but no issues or pull requests were merged in the last month, so current project responsiveness is not demonstrated.
The repository has no published security policy, reducing transparency about vulnerability reporting and handling for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
nunomaduro/termwind Version ^2.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.