The package has solid documentation, tests, release notes, and a matching repository, with no install-time scripts. Its current maintenance pause and unpinned GitHub Actions reduce confidence for a long-term dependency.
65%
Total Score
50
100
94
67
The registry namespace and repository are owned by the same individual, so the package has direct ownership alignment but no organizational backing shown by this signal. This is acceptable for a small project but leaves a relatively narrow support base.
The package has 67 releases since 2019, but none in the last 12 months; the latest release was over a year before collection. This indicates a meaningful maintenance slowdown despite its established history.
There were zero commits and zero active maintainers in the preceding three months. Combined with no registry releases in the last 12 months, this is a concrete abandonment-risk concern.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it is a moderate documentation gap rather than evidence that the package is unfit.
All six workflows were analyzed successfully with no reported findings, dangerous triggers, or untrusted checkouts. However, all 10 action references are unpinned, leaving the build exposed to moving action code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.53.1|^3.0 | — | — |
guzzlehttp/guzzle Version ~6.0|~7.0 | — | — |
illuminate/support Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.