The repository has made no commits in the last three months, despite a recent release and a long project history. Workflow actions are all unpinned, and a high-confidence bot-condition finding adds maintenance hygiene risk; tests, release notes, licensing, and security tooling are present.
66%
Total Score
50
94
100
The package has existed for over six years with 21 releases, but only one release in the last 12 months; the recent v4.0.0 release partly offsets the slower cadence.
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance warning even though the package has a recent release.
All 11 analyzed action references are unpinned, and the audit found a high-confidence bot-condition issue; the pull_request_target workflow has no untrusted checkout or script-injection sink, limiting the risk to workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.