Risky to adopt: the package has had no release or repository activity for about 3 years and 11 months. It is documented, licensed, and not deprecated, but the prolonged inactivity makes maintenance and compatibility uncertain.
42%
Total Score
0
81
67
Only two releases were published, both on October 18, 2022, with no releases in the last 12 months. This prolonged release gap is a substantial maintenance concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's nearly four-year release hiatus and indicating strong abandonment risk.
One of five workflows uses pull_request_target, which deserves review because that trigger can expose privileged workflow behavior to pull requests. No untrusted checkouts or script-injection patterns were detected, limiting the concern.
The repository has zero stars, forks, and watchers, providing no community-use evidence to compensate for its long inactivity. Popularity is supporting evidence rather than decisive on its own.
Four workflows lack top-level token permissions, and the Dependabot auto-merge workflow grants top-level write access. This is weaker than least-privilege workflow hygiene, although no broader workflow exploit was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
sawirricardo/midtrans-api Version ^1.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.