The MIT license, clear README, changelog, repository tests, and organization backing support routine adoption. Its small dependency footprint and matching repository improve transparency, though consumers should expect a young pre-1.0 API.
62%
Total Score
100
100
83
50
The package has only three releases and none in the last 12 months; its latest registry release was about 16 months ago. The repository was pushed more recently, which partly offsets but does not remove the release-cadence concern.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a modest transparency gap for a package handling external API credentials.
Version 0.3.0 is not a stable major release, so its API may still change. It is not marked as a prerelease, which provides some compensation for production use.
All 12 action references are unpinned, and three workflows grant top-level write permissions. The high-confidence bot-conditions finding in the Dependabot auto-merge workflow adds workflow hygiene concern, although no untrusted checkout or script injection was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^12.0 | — | — |
illuminate/support Version ^12.0 | — | — |
illuminate/contracts Version ^12.0 | — | — |
meteocontrol/vcom-api-client Version ^3 | — | — |
spatie/laravel-package-tools Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.