The repository has no security policy, and its only workflow uses a broad write token with an unpinned action. Clear licensing, documentation, and release notes provide useful transparency despite the maintenance gap.
59%
Total Score
75
100
88
67
The latest release was on May 30, 2025, and there were no releases in the following 12 months of observed history. This suggests the package may be stalled, although the seven-release history provides some maturity evidence.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the absent recent releases, this is meaningful evidence of stalled maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance concern, not a severe risk by itself.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures unclear for an editor package that embeds an unsupported TinyMCE version.
The workflow audit completed fully and found no high-confidence dangerous sinks, but its only workflow grants top-level write permissions and uses its sole action unpinned. Without an untrusted trigger or checkout, this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.