The package has clear documentation, repository tests, and release notes for this version. Its single-maintainer base and fully unpinned workflow actions add maintenance and build-integrity concerns, despite recent release activity and active repository status.
68%
Total Score
50
100
100
50
Only one account has registry publishing access. The linked repository is owned by the same individual, so this is consistent ownership but still leaves limited observable publishing redundancy.
The registry namespace and repository owner match, and the owner is an individual rather than an organization. This supports package identity but provides limited organizational maintenance depth.
There were no commits and no active maintainers in the three months measured. The recent repository push and release history partly offset this, but the current maintenance pace is a concern.
No repository security policy was found. This is a transparency gap for reporting and handling vulnerabilities, though it is not evidence of an unsafe release by itself.
Both workflows were analyzed successfully with no high- or medium-confidence findings, no untrusted checkouts, and no script-injection paths. However, all 6 of 6 action references are unpinned, which weakens build reproducibility and supply-chain integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.0|^13.0 | — | — |
markwalet/laravel-git-state Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.