The repository is organization-backed and includes tests, release notes, security scanning, and a security policy. Pinning workflow actions would improve its otherwise solid maintenance and supply-chain hygiene.
70%
Total Score
75
92
75
The package has 114 releases across about 9 years, but only 1 release in the last 12 months. The recent v11.0.0 release provides some evidence of ongoing maintenance, though the current cadence is limited.
There were 0 commits and 0 active maintainers in the last 3 months. A recent release and a repository pushed within the observed period provide some compensation, but the lack of recent commit activity still raises maintenance concern.
All 4 workflows use read-only permissions and the audit found no injection, untrusted checkout, or high-severity findings. However, all 12 analyzed action references are unpinned, leaving avoidable update and supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
orchestra/testbench Version ^11.0.0 | — | — |
symfony/dom-crawler Version ^7.4|^8.0 | — | — |
laravel/browser-kit-testing Version ^7.2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.