Clear licensing, detailed documentation, and release notes make adoption easier. Maintenance depends on the organization’s capacity, since only one contributor committed recently and workflow actions are unpinned.
68%
Total Score
67
100
50
All recent repository commits came from one contributor, creating a real maintenance concentration risk. Organization ownership provides some backing, but no second active contributor is shown.
Only two commits occurred in the last three months, showing limited recent development activity despite the latest release being current.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The single workflow was fully analyzed with no dangerous audit findings, but both action references are unpinned, so their dependencies can change without a repository commit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.0 | — | — |
sendynl/php-sdk Version ^1.0 || ^3.0 | — | — |
marshmallow/helpers Version ^v2.12.1 | — | — |
marshmallow/commands Version ^v1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.