The package includes tests in its repository, release notes, a matching source project, and an MIT license. Maintenance is still uncertain because it has only one release and no commits from any active maintainer in the last three months; workflow weaknesses add adoption risk.
58%
Total Score
75
88
50
This is a 173-day-old package with only one release, so there is little release history from which to judge sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful sign of currently inactive development.
The repository has one star, no forks, and no watchers. Popularity is only supporting evidence, but these figures provide little external evidence of maturity or broad adoption.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for a package that handles personal-data and compliance features.
All 10 action references are unpinned, and the audit found a high-confidence bot-condition issue in a Dependabot auto-merge workflow; top-level write permissions also appear in two workflows, although no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0 | — | — |
lumensistemas/encryption-laravel Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.