Documentation, licensing, repository tests, and release notes make the package easier to evaluate. The remaining maintenance and workflow gaps make a long-term dependency choice risky.
48%
Total Score
0
75
50
This is the package's only release, published two years ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the absence of recent maintenance evidence.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.1 is an early release rather than a stable major version, which adds maturity risk alongside the single-release history.
All five analyzed action references are unpinned and one workflow grants top-level write permissions. No untrusted trigger, checkout, or script-injection sink was found, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
php-amqplib/php-amqplib Version ^3.7 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.