The package includes tests, a changelog, release notes, a matching repository, and an MIT license. Its single-release history, absent recent commits, missing security policy, and workflow weaknesses reduce confidence in long-term support.
55%
Total Score
50
93
50
This is the only release, published about 17 months ago, with no releases in the last 12 months. That leaves limited evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers during the last 3 months. Combined with the single release, this raises abandonment concerns.
There were no new or closed issues or pull requests in the last month, while 6 pull requests remain open. This suggests limited recent project activity.
The repository has no security policy. That is a transparency and response-process gap for a package used in application development.
All 12 analyzed action uses are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-permission Version ^6.17 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
spatie/laravel-query-builder Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.