The source repository has tests, a changelog, and release notes, while the package is licensed and uses no install-time scripts. If you adopt it, pin the exact version and review its unpinned CI actions.
58%
Total Score
50
92
75
The latest release was in February 2023, with no releases in the past 12 months despite the package being over four years old. This is a meaningful maintenance concern, although the repository remains unarchived and has a release note for this version.
The repository had zero commits and zero active maintainers in the past three months, consistent with a long period of limited visible maintenance. The repository was last pushed in March 2024, which provides some evidence it was maintained previously but does not offset the current inactivity.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though the repository does include tests and a changelog.
All 5 of 5 analyzed action references are unpinned, creating avoidable build reproducibility and action-update risk. However, both workflows were fully analyzed, had no dangerous triggers or untrusted checkouts, and produced no audit findings, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pestphp/pest Version ^1.17 | — | — |
illuminate/support Version ^8.76|^9.0|^10.0 | — | — |
pestphp/pest-plugin Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.