The package has clear licensing, tests, release notes, and a security policy. Its source repository is archived, no commits were made in the last three months, and the registry marks the package abandoned, so it should not be adopted for new projects.
18%
Total Score
0
63
83
Packagist marks the entire package as abandoned, with no replacement named. This is a direct warning against taking a new dependency on the package.
The last release was about four years ago, and there were no releases in the preceding 12 months. The short historical release intervals do not compensate for the prolonged halt.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the archived state and old release history, this indicates abandonment rather than a temporary pause.
The linked repository is archived, which strongly indicates that active maintenance has ended. Its last push was about 18 months before collection, with no evidence of ongoing stewardship.
All eight analyzed action references are unpinned, and high-confidence findings identify spoofable bot conditions and an unpinned container image. The audit was complete, but these workflow weaknesses reduce build transparency and reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^5.0|^6.0 | — | — |
symfony/filesystem Version ^6.0 | — | — |
illuminate/contracts Version ^8.73|^9.0 | — | — |
ralphjsmit/filesystem Version ^1.2 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.