The organization-backed repository is active, unarchived, and supported by tests, release notes, and clear package matching. Maintenance is concentrated in one contributor, and all 17 workflow actions are unpinned.
68%
Total Score
83
93
75
The package has 29 releases over nearly eight years, but none in the last 12 months; recent repository activity partly offsets the slower registry cadence.
All 4 recent commits came from one contributor, leaving maintenance dependent on a single active person; organization backing provides some handoff capacity but does not remove the concentration.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were analyzed without dangerous triggers or audit findings, and one scopes permissions at job level. However, all 17 action references are unpinned, weakening build reproducibility and action supply-chain controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/regex Version ^1.4 || ^2 || ^3 | — | — |
webonyx/graphql-php Version ^15 | — | — |
thecodingmachine/safe Version ^1.3 || ^2 || ^3 | — | — |
egulias/email-validator Version ^2.1.17 || ^3 || ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.