The project has only two stars, no security policy, and a single registry maintainer, though organization backing partly offsets the last concern. Its documented tests, changelog, MIT license, regular releases, and non-archived repository support adoption, while workflow references are not pinned.
68%
Total Score
67
94
75
The repository recorded zero commits and zero active maintainers in the last three months, indicating a recent maintenance pause despite the newer push timestamp elsewhere in the repository metadata.
There were no new or closed issues or pull requests in the last month, while four pull requests remain open; this suggests limited recent project interaction.
The repository has only 2 stars, 2 forks, and 2 watchers. Popularity is not decisive, but this provides little independent evidence of broad community adoption or review.
No security policy is present in the repository, leaving vulnerability reporting and response expectations undocumented.
All 11 analyzed action references are unpinned, weakening build reproducibility and making workflow dependencies easier to change unexpectedly. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings, which limits this to a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^3.7|^4.2 | — | — |
spatie/laravel-package-tools Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.