Usable with caveats: this is a correctly backed, licensed package with tests, a changelog, release notes, and build/security tooling. However, it has only one release and no commits or active maintainers in the last three months, while workflow permissions and security-policy documentation are incomplete.
62%
Total Score
50
100
94
50
One workflow-run workflow uses an untrusted checkout, which creates avoidable CI supply-chain exposure even though no pull_request_target or script-injection patterns were found.
One registry publishing account is a limited operational base, although the matching repository ownership and the project's very recent first release partly explain this.
The registry namespace and repository owner match, and the owner is an individual user. This supports ownership continuity but offers less organizational backing than a maintained organization-owned project.
The package is only 147 days old and has one release, so there is not enough history to establish dependable release maintenance.
There were zero commits and zero active maintainers during the last three months. Because the package is new and its only release was 147 days ago, this is a meaningful but not conclusive maintenance warning.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/scout Version ^11.0 | — | — |
elasticsearch/elasticsearch Version ^8.16|^9.0 | — | — |
handcraftedinthealps/elasticsearch-dsl Version ^8.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.