The package is thoroughly documented, tested in its repository, and backed by an organization. Its maintenance record is too new to establish reliability, while the workflow lacks pinned actions and uses broad write permissions.
60%
Total Score
75
100
88
50
This is the package's first registry release, published on the collection date, so there is no release history or cadence demonstrating sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. Because the project is newly published, this is partly explained by its age, but it still leaves maintenance capacity unproven.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap for a package handling authentication, permissions, and API data.
The repository has no security policy, so users have no documented channel or process for reporting vulnerabilities.
The complete workflow audit found no injection or high-severity findings, but all four action references are unpinned and the only workflow grants top-level write permissions, weakening build reproducibility and token least privilege.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.0|^3.0 | — | — |
laravel/framework Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.