The package has clear documentation, tests in its repository, a license, and security tooling. Its release and commit activity has stopped, while the workflow audit found an unsafe bot-condition check and no pinned actions.
58%
Total Score
50
94
100
The latest release was over 3 years ago, with no releases in the last 12 months. Six releases over the package's history show some maturity, but the long release gap raises abandonment risk.
The repository had 0 commits and 0 active maintainers in the last 3 months. This supports the concern raised by the stale registry release history.
All 11 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in a pull_request_target workflow with top-level write permissions. There was no untrusted checkout or script injection, so this is a workflow hygiene concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^9.0|^10.0 | — | — |
jackiedo/dotenv-editor Version ^2.0 | — | — |
spatie/laravel-package-tools Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.