It has an MIT license, tests, release notes, and a security policy, which support transparency and maintenance. The repository also has build and security tooling, but the overall evidence does not offset the registry status and weak recent activity.
22%
Total Score
25
81
75
The registry marks the entire package as abandoned and provides no clear deprecation explanation; this is a severe adoption risk even though a replacement name is listed.
The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the package's abandoned registry status and raising maintenance risk.
There were no new or closed issues or pull requests in the last month, while one issue and two pull requests remain open; this supports the picture of weak current activity.
The linked repository name does not match the package name and its README does not mention the package, so the package-to-source relationship is not clearly established despite the repository's organization backing.
All 10 analyzed action references are unpinned, and the audit found two high-confidence template-injection findings. No untrusted checkout or script-injection trigger was reported, so this is a hygiene and build-integrity concern rather than a standalone severe finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.2 | — | — |
symfony/process Version ^7.2 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
laravel/installer Version ^5.12 | — | — |
illuminate/support Version ^11.42.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.