Organization ownership and a stable major version provide useful continuity. The source is well documented and tested, but three unpinned workflow actions and no security policy leave avoidable transparency and build-hygiene gaps.
72%
Total Score
75
83
50
Six releases since April 2025 and two releases in the last 12 months show a real release history, but the latest release was about nine months ago, indicating slower recent delivery.
The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the recent release and organization backing reduce abandonment concern.
The repository has no published security policy. That is a transparency gap for a library, though it does not by itself indicate that the release is unsafe.
The only workflow was fully analyzed with no dangerous sinks or audit findings, but all three action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions weaken build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
opis/json-schema Version ^2.6 | — | — |
laravel/framework Version >=12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.