The package has a clear MIT license, a matching repository, repository tests, and release notes for this version. A single maintainer and the limited project history leave less evidence of durable long-term support.
58%
Total Score
50
100
94
50
All 12 analyzed action references are unpinned, and three workflows grant top-level write permissions. A high-confidence bot-conditions finding occurs in a pull_request_target workflow, making the automation hygiene materially weaker even though no untrusted checkout or script-injection sink was found.
Only one registry account has publish access, and the project is user-owned rather than organization-backed. That creates a thin publishing and continuity base, although access records alone do not establish actual activity.
The registry namespace and repository are owned by the same individual account, and no organization backing is shown. This matches the single-maintainer picture and provides limited continuity assurance.
All six releases occurred within roughly 17 minutes on the same day, so the package has little demonstrated release cadence despite being about 9 months old. That limits evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. For a package released in a concentrated burst, this provides weak evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^6.0|^7.0 | — | — |
illuminate/contracts Version ^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.