The workflow uses three unpinned actions, and the repository has no security policy or security scanning. Its matching, tested repository is not archived and produced a release within the last year, which supports continued ownership despite no commits in the past three months.
70%
Total Score
75
100
89
83
The package has 52 releases over roughly seven years, but only one release in the last 12 months, indicating a slow recent cadence rather than abandonment by itself.
The repository recorded zero commits and zero active maintainers in the past three months. The recent registry release and push offset this, but the lack of ongoing development lowers maintenance confidence.
There are no open issues or pull requests, and no issue or pull-request activity in the past month; this is neutral to mildly cautionary because it shows little visible community activity.
Composer build tooling is present, but no security scanning tools are configured, leaving security-related maintenance less visible.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.1 || ^12.1 | — | — |
intervention/image Version ^3.7 | — | — |
reliqarts/laravel-common Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.