The matching repository, MIT declaration, and modest dependency set provide useful transparency. Maintenance stopped in December 2022, and the workflow combines pull-request-target execution with an untrusted checkout and nine unpinned actions.
35%
Total Score
0
100
71
50
The package has had no releases in more than four years: its latest release was March 26, 2022, with zero releases in the last 12 months. This is strong evidence of abandonment risk for a Laravel library.
The repository had zero commits and zero active maintainers in the last three months. Combined with the last push in 2022, this indicates the project is no longer receiving active maintenance.
The repository name matches the package name, supporting that the linked source belongs to this package. Its README does not mention the package explicitly, a minor transparency weakness rather than evidence of repository misattribution.
The release is presented as v2.5.3, while the collected stability profile reports v2.2.2 as the latest version. That inconsistency weakens release transparency and warrants caution alongside the stale release history.
The only workflow uses pull_request_target with an untrusted checkout, which creates a meaningful exposure to untrusted code, and all 9 action references are unpinned. The audit found no high-confidence rule findings, but these workflow practices still reduce supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ro/dto-php Version ^1.0 | — | — |
illuminate/support Version ^8.82|^9.0 | — | — |
illuminate/contracts Version ^8.82|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.