Clear licensing, repository tests, and a matching source make the package transparent. The release line is about four years old with no commits in the last three months, while workflow references are entirely unpinned. Pin version 2.0.0 only if its Laravel support remains suitable.
62%
Total Score
75
100
93
75
The latest registry release was about four years ago, with no releases in the last 12 months. That materially raises abandonment and compatibility risk despite the stable major version.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the repository remains available and is organization-owned.
No repository security policy was found. This is a transparency gap, but it is limited because the project has Dependabot scanning and no evidence here of a security incident.
All five analyzed action references are unpinned, which weakens build reproducibility. The reported cache-poisoning issue has low confidence and is hygiene at most; the audit otherwise found no untrusted checkout or script-injection path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/horizon Version ^5.8 | — | — |
renoki-co/laravel-exporter-contracts Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.