The source repository has tests, a release note for this version, and three active contributors. Its lack of a security policy and completely unpinned workflow actions leave avoidable maintenance and build-integrity gaps.
68%
Total Score
100
100
79
75
The package is only about 2 months old, with 3 releases in that period and a median interval of about 2 days; this shows active initial development but limited long-term history.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, which makes vulnerability-reporting and coordinated disclosure expectations less clear for dependents.
Version v0.1.1 is not from a stable major series, so its API and behavior may change more readily than those of a mature release line.
All 8 analyzed action references are unpinned, and 2 of 3 workflows grant top-level write permissions. The audit found no untrusted checkout, script injection, or higher-severity findings, so this is a hygiene and token-scope concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^4.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
saloonphp/laravel-plugin Version ^4.0 | — | — |
saloonphp/rate-limit-plugin Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.