Clear documentation, tests, and two active contributors provide useful support for adoption. The project has no security policy or scanning, and both workflow actions are unpinned, so maintenance and build hygiene still need attention.
72%
Total Score
83
100
88
75
This is the package's only release, published 95 days ago, so its long-term maintenance record is still unproven. Recent repository activity and two contributors partly offset the short history.
Two commits were made in the last three months, with activity from two maintainers. That is limited activity for a young package but does show recent maintenance.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a modest transparency and maintenance gap for a package intended for application use.
The repository has no security policy. This does not show a vulnerability, but it leaves the process for reporting and handling security issues unclear.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or high-confidence audit findings. However, both of its action references are unpinned, leaving builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.72|^3.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.93 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.