The repository includes tests and release notes, and the package is clearly tied to its organization. Security scanning is absent and one workflow grants broad write access, adding maintenance and build-hygiene concerns.
68%
Total Score
75
100
94
75
There were no commits and no active maintainers in the last three months, despite a release about four months before collection. The recent release history partly offsets this, but the current pause is a maintenance caution.
Composer is used for builds, but no security-scanning tools are configured. The missing scanning is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear and modestly reduces project transparency.
All 8 analyzed action references are unpinned, which weakens build reproducibility. One workflow grants top-level write permissions, but there are no untrusted checkouts, script injections, or high-confidence audit findings, limiting the impact to caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/url Version ^2.0 | — | — |
phpunit/phpunit Version ^10.0|^11.0|^12.0 | — | — |
symfony/dom-crawler Version ^6.1|^7.0 | — | — |
illuminate/macroable Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.