The package includes tests, release notes, and a matching repository, with no install scripts or deprecation notice. Its workflow uses an unpinned container image, and the project has no recent security tooling or policy.
48%
Total Score
50
100
81
75
Although the package has five releases over roughly six years, it has had no release in the last four years; the latest release was June 2022. That is a substantial maintenance and abandonment concern.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the four-year release gap and increasing abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and disclosure guidance undocumented. This matters for a dependency but is not severe on its own.
Both workflows were analyzed successfully and have no untrusted triggers or script-injection findings, but all five action references are unpinned and the audit found a high-confidence unpinned container image. This is avoidable build-integrity hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^9.15 | — | — |
spatie/data-transfer-object Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.