This is a reasonably established and actively published package with a stable 1.1.0 release, five releases in the last 12 months, a matching organization-owned repository, an MIT license, a changelog, and build plus Dependabot tooling. However, the repository shows no commits or active maintainers in the last 3 months despite the latest release, has no tests, lacks a security policy, and includes workflows with broad or unspecified token permissions plus one pull_request_target workflow. It is usable for dependency adoption, but the thin observable maintenance activity and workflow hygiene warrant review before relying on it in a security-sensitive or long-lived project.
68%
Total Score
75
50
89
60
Four workflows were analyzed; one uses pull_request_target, which can elevate workflow risk. No untrusted checkout or script-injection patterns were detected, partially compensating for the concern.
Five runtime dependencies are declared, including several organization-maintained packages and a webhook server library. The dependency surface is material but not unusually large for this integration package.
The package uses a post-autoload-dump install-time script. This adds execution during installation and should be reviewed, although the signal does not show that the script is destructive or otherwise unsafe.
A substantial README and changelog are present, and the repository uses GitHub Releases, but neither the artifact nor repository contains tests. The missing tests are a genuine verification gap for a library package.
The repository recorded zero commits and zero active maintainers in the last 3 months. Although the latest release was pushed recently, the observed short-term development inactivity is a meaningful maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opscale-co/actions Version ^3.0 | — | — |
opscale-co/validations Version ^1.0 | — | — |
opscale-co/nova-package-tools Version ^1.1 | — | — |
spatie/laravel-webhook-server Version ^3.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.