The MIT license, repository tests, and changelog provide a usable foundation. The minimal README and missing security policy add transparency gaps, while the thin release and commit history raise long-term support concerns.
43%
Total Score
0
63
50
This package has made only one release, with no releases in the last 12 months, and the sole release was 543 days ago. That is substantial abandonment risk for a package still at version 0.1.
There were zero commits and zero active maintainers in the last three months, consistent with the package's single-release history. This materially increases the chance that defects or compatibility issues will remain unattended.
The linked repository has no security policy, leaving maintainers' vulnerability-reporting process unclear. This is a transparency gap, though it is less serious than the observed lack of maintenance activity.
Version 0.1 is not a stable major release, so compatibility and project maturity remain uncertain. The absence of any later release reinforces that this is an early, unproven dependency.
All 12 action references are unpinned, three workflows grant top-level write permissions, and the high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so these are workflow-hygiene concerns rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-health Version ^1.23 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.