The repository has had no commits for about three months, and its workflows use broad write permissions with six unpinned actions. Documentation, licensing, tests in the repository, security scanning, and a release note for this version provide useful support, but the project is still young.
63%
Total Score
50
100
93
75
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to offset the thin maintenance record.
The repository recorded zero commits and zero active maintainers during the last three months. That is a meaningful maintenance concern, although the package has a short release history and was pushed in early July.
The repository has no security policy. For a package implementing authentication and a network-facing WebDAV server, that leaves vulnerability reporting and handling less transparent.
Version 1.0.0 is a stable major release, but 87.5% of recent releases were prereleases, so the project's stable-release track has limited history.
All six analyzed action references are unpinned, and all three workflows grant top-level write permissions. The audit also found a high-confidence bot-condition issue in the Dependabot auto-merge workflow; the pull_request_target trigger had no untrusted checkout or script-injection sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabre/dav Version ~4.7.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.