The package includes tests, release notes, a matching repository, and a clear MIT license. Its dependency and workflow setup are straightforward, but there is no recent maintenance to support continued adoption.
12%
Total Score
0
100
58
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the registry explicitly signals that maintenance has ended.
The repository recorded no commits and no active maintainers in the past three months. This confirms the lack of ongoing development rather than merely a slow release cadence.
The linked repository is archived, and its last push was in March 2023. An archived source project is a strong indication that future fixes and compatibility updates are unlikely.
The package has only two releases, with the latest in February 2023 and none in the past 12 months. This limited and inactive release history supports the abandonment concerns.
The single workflow was fully analyzed with no untrusted checkout, script injection, or auditor findings. However, all three action references are unpinned, which is a minor reproducibility and supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pboivin/flou Version ^1.0 | — | — |
laravel/framework Version ^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.