It has a clear README, an exact repository match, and normal dependency and install behavior. The long release gap and inactive recent commit window make pinning 6.3.1 preferable to tracking updates.
67%
Total Score
67
100
94
75
The registry namespace and repository are owned by the same individual, so ownership is consistent, though the project does not have organization backing to broaden maintainer capacity.
The package has 21 releases over roughly 12 years, but none in the last 12 months; the latest registry release was about 19 months before collection. This weakens confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last 3 months, a concrete sign of currently inactive development and increased abandonment risk.
No repository security policy was found, leaving vulnerability-reporting guidance undocumented. This is a transparency gap, but not by itself evidence that the package is unsafe.
All four workflows were analyzed, but all 8 action references are unpinned. The audit also found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow and top-level write permissions there; the pull_request_target trigger has no untrusted checkout or script-injection sink, limiting the impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/apiclient Version ^2.16 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.