The package has clear licensing, documentation, tests, regular releases, and an active repository. Maintenance is concentrated in one contributor, while workflow permissions, unpinned actions, and a high-confidence automation warning add avoidable supply-chain risk.
60%
Total Score
50
100
100
25
All 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The audit found no untrusted checkout or script-injection sinks, which limits the severity but does not remove the hygiene risk.
Only one account has registry publishing access. The repository is user-owned rather than organization-owned, so the short maintainer base is a genuine continuity concern.
The source repository is owned by a user account rather than an organization, so the single-contributor and single-publisher concentration is not offset by visible organizational backing.
One contributor made all commits in the last three months, leaving maintenance fully concentrated in a single person with no provided organizational backing.
Only one commit was recorded in the last three months, indicating limited recent development despite the package's recent release activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nycorp/lite-api Version ^1.1 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.