The repository remains intact and has tests, a clear license, and organization backing. Workflow permissions and unpinned actions add maintenance risk, especially alongside the stale development activity.
54%
Total Score
75
92
The latest release was over two years ago, with no releases in the last 12 months and only seven releases overall. This materially lowers confidence that the package is actively maintained.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the release-history concern rather than showing current maintenance.
All 12 analyzed action references are unpinned, and three workflows grant top-level write permissions. The high-confidence bot-conditions finding also warrants workflow hygiene caution, although no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^9.0|^10.0|^11.0 | — | — |
spatie/laravel-health Version ^1.23 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
laravel-notification-channels/google-chat Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.