The package is clearly documented and has a matching source repository, but its maintenance appears to have stopped. Missing security tooling and unpinned workflow actions add smaller transparency and build-integrity concerns.
38%
Total Score
0
79
75
The latest release was about 5 years and 11 months ago, with only 2 releases overall and none in the last 12 months. This is strong evidence of abandonment for a package that may need compatibility updates.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and leaving no evidence of current maintenance capacity.
The repository is not archived, which preserves a path for maintenance, but its last push was about 5 years and 11 months ago and does not offset the inactivity shown elsewhere.
The repository has no security policy. This is a transparency gap, although it is less significant than the package's prolonged inactivity.
The workflow audit completed successfully and found no dangerous triggers, untrusted checkouts, or audit findings. However, all 3 analyzed action references are unpinned, leaving a modest build-integrity weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.4 | — | — |
spatie/laravel-dashboard Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.