The repository includes tests, release notes, dependency scanning, and a clear MIT license. The long gap since the last registry release and workflow hygiene issues make ongoing maintenance less certain.
65%
Total Score
50
94
75
The latest release was over two years ago, with no releases in the past 12 months. This is a meaningful maintenance concern, although the repository was pushed recently and had three merged pull requests in the last month.
There were no commits and no active maintainers in the past three months, which weakens evidence of ongoing development. Recent repository pushes and merged pull requests provide some compensating activity but do not restore a regular release cadence.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. Dependabot is enabled, which provides some compensating security practice.
All 9 analyzed action references are unpinned, and a high-confidence bot-conditions finding reports that actor checks may be spoofable; one workflow also grants top-level write permissions. The pull_request_target workflow has no untrusted checkout or script-injection finding, so this is workflow hygiene risk rather than a severe release risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
spatie/color Version ^1.5 | — | — |
illuminate/collections Version ^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.