The package is clearly documented, licensed, and supported by repository tests and security tooling. It has made only one release, with no commits or active maintainers in the last three months. Workflow checks also found a high-confidence bot-condition issue and all action references are unpinned.
58%
Total Score
50
89
75
The repository is owned by an individual account rather than an organization, so there is no demonstrated organizational maintenance cushion. This matters alongside the lack of recent commit activity.
This is a new package, about 9 months old, but it has only one release and no demonstrated release cadence. That limits evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers during the last 3 months. For a package with only one release, this is meaningful evidence that maintenance may have stalled.
The repository has 1 star, 0 forks, and 0 watchers. Low popularity is only supporting evidence, but it provides little external evidence of maturity or community support.
All five workflows were analyzed, but all 12 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. Top-level write permissions in three workflows add further workflow hygiene concern, though no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
ritechoice23/laravel-saveable Version ^1.0 | — | — |
ritechoice23/laravel-reactions Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.