The package includes tests, release notes, a clear MIT license, and an active-looking organization-backed repository. Its 11 workflow actions are all unpinned, and no security policy or recent maintenance activity is visible, so future fixes and build integrity deserve caution.
58%
Total Score
100
88
50
The package runs a post-install Composer lifecycle script. This is a meaningful installation-time behavior that should be reviewed, though it is not by itself evidence that the package is unsafe.
The package has 24 releases over roughly three years, but none in the last 12 months; the latest release was published on October 7, 2024. This indicates a sustained maintenance pause.
The repository uses Composer build tooling but reports no security scanning tools. The missing scanning is a hygiene gap, while the build tooling itself is appropriate.
The repository has no published security policy, reducing transparency about vulnerability reporting and response expectations.
All four workflows were analyzed without high-severity findings or untrusted checkouts, but all 11 action references are unpinned. Unpinned actions weaken reproducibility and supply-chain integrity even though no dangerous trigger or sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pestphp/pest Version ^3.0 | — | — |
tightenco/duster Version 3.0.0 | — | — |
larastan/larastan Version ^2.0 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
pestphp/pest-plugin-laravel Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.