The MIT license, complete README, repository tests, and Dependabot provide a solid baseline. GitHub Actions use broad write access and all 12 action references are unpinned, so build hygiene needs attention.
64%
Total Score
50
83
50
This is the first recorded release and the package was published today, so there is no release track record or demonstrated cadence yet. That is expected for a new package but still limits confidence.
The repository has no commits in the last 3 months and no active maintainers during that period. Because the package was released today, this is more likely limited history than evidence of abandonment, but maintenance is not yet demonstrated.
The repository has no security policy. For a client handling OAuth credentials and external API access, that is a modest transparency and maintenance gap.
The assessed version is v0.1 rather than a stable major release, which signals an early API and maturity stage. It is not marked prerelease, so the concern is limited to its early versioning.
All 5 workflows were analyzed with no audit findings or untrusted checkouts, but all 12 action references are unpinned and 3 workflows grant top-level write permissions. The pull_request_target trigger has no reported sink, so this is workflow hygiene rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-data Version ^4.23 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.