The package is clearly documented, licensed, and has release notes for this version. Its repository is actively developed with four recent contributors, though most commits come from one person and six of eight workflow actions are unpinned.
78%
Total Score
100
100
81
75
Only one release has been published, 53 days after the first release, so long-term maintenance and release continuity are not yet demonstrated.
Composer build tooling is present, but no security-scanning tool was detected; the repository's separate security policy and workflow audit provide some compensating transparency.
Version v0.1.0 is not a stable major release, which signals an early API and maturity stage even though it is not marked as a prerelease.
All four workflows were analyzed with no auditor findings, no untrusted checkouts, and read-only permissions in three workflows. However, six of eight action references are unpinned and one workflow has top-level write permissions, leaving moderate reproducibility and token-scope hygiene gaps.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.0 | — | — |
laravel/prompts Version ^0.3.21 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/process Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.