The package has a steady release history and a matching repository with tests, but recent commit activity is absent. Workflow dependencies are all unpinned, and no security policy is published, leaving maintenance and build-hygiene concerns.
68%
Total Score
75
100
94
50
One registry publishing account is consistent with the repository being owned by the same individual; this is limited publishing capacity but not evidence of abandonment by itself.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance warning despite the recent release history.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance-hygiene gap.
The repository has no security policy, reducing the clarity of vulnerability-reporting and response expectations for a package that interfaces with an external API.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, or audit findings, but all 7 action references are unpinned, which weakens build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.9 | — | — |
spatie/laravel-data Version ^4.13 | — | — |
caseyamcl/guzzle_retry_middleware Version ^2.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.