It includes a clear README, tests, release notes, and an MIT license. The repository is new, with no recorded commits in the last three months, and its workflow uses three unpinned actions. Pin v3.1.0 and watch for follow-up releases.
64%
Total Score
50
86
67
This is the package's first release, published today, so there is no established release cadence or maintenance history yet.
The repository recorded zero commits and zero active maintainers in the last three months. Because the package was released today, this mainly shows that an established activity record is not yet available.
Composer is used for builds, but no security scanning tool was detected, leaving a modest repository-hygiene gap.
The repository has no security policy, making the process for reporting and handling vulnerabilities unclear.
The single workflow was fully analyzed without dangerous triggers or audit findings, but all three action references are unpinned. Pinning them would reduce build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dedoc/scramble Version ^0.13.13 | — | — |
tymon/jwt-auth Version ^2.1 | — | — |
laravel/framework Version ^10.0|^11.0|^12.0|^13.0 | — | — |
maatwebsite/excel Version ^3.1 | — | — |
spatie/eloquent-sortable Version 3.*|4.*|5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.