A complete README, MIT license, repository tests, and Dependabot provide useful transparency. Compatibility fixes may be difficult to obtain if framework or database requirements change.
43%
Total Score
25
83
50
This is the only release, published 3 years and 2 months ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with a project that has been inactive for over three years.
Only one registry publishing account is listed. Because the repository is user-owned rather than organization-backed, this indicates a thin publishing base and limited continuity if the maintainer stops responding.
All 9 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.5 | — | — |
jmikola/geojson Version ^1.0 | — | — |
geo-io/wkb-parser Version ^1.0 | — | — |
illuminate/database Version ^10.0 | — | — |
illuminate/contracts Version ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.