It includes a clear MIT license, useful documentation, repository tests, and Dependabot. The stable 1.0.0 release has had no newer maintenance activity, so future Laravel compatibility may require your team to take over.
61%
Total Score
75
100
89
67
This is the only release, published about 2 years and 10 months ago, with no releases in the last 12 months. That leaves compatibility and bug-fix maintenance uncertain.
There were zero commits and zero active maintainers in the last 3 months, consistent with the repository's last push in November 2023. This is the main abandonment concern.
The repository has zero stars, forks, and watchers. Popularity is not decisive, but this provides no supporting evidence of broad community use or review.
The repository has no security policy. This is a transparency gap for a package that handles provider credentials, though it is not evidence of unsafe code by itself.
The only workflow was fully analyzed with no dangerous triggers, sinks, or audit findings. However, both action references are unpinned, leaving a modest workflow-reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3.1|^7.0.1 | — | — |
laravel/framework Version ^6.0|^7.0|^8.0|^9.0|^10.0 | — | — |
spatie/array-to-xml Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.