It includes a substantial README, tests, an MIT license, and a matching repository, which improve transparency. The single maintainer, absent security policy, and unpinned workflow actions leave limited safety and continuity evidence.
61%
Total Score
50
80
50
This is the package's only release, published 167 days ago, so there is little release history to demonstrate sustained maintenance.
The repository had zero commits and zero active maintainers in the last three months, despite being only 167 days old; this weakens evidence of ongoing maintenance.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or describing security handling.
Version v0.0.2 is not a stable major release, indicating an early-stage API and greater compatibility risk for dependents.
The workflow audit completed successfully with no untrusted checkouts, script injection, or audit findings. However, both of its two action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.