Address formatter for Laravel powered by commerceguys/addressing
62%
Total Score
caution
Usable with caveats: maintenance has gone quiet and the release workflows have notable hygiene risks.
The package has four releases over about four years, with no releases in the last 12 months and a median interval of about 343 days. This indicates slow maintenance, though not abandonment by itself.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance warning, although the repository is not archived and was pushed recently.
The linked repository has no security policy. This is a transparency gap for reporting vulnerabilities, though dependency scanning through Dependabot provides some compensating security process.
The audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow, and all nine analyzed action references are unpinned. The pull_request_target workflow has no untrusted checkout or script-injection sink, which limits the severity, but the workflow hygiene still lowers confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^9.0|^10.0|^11.0|^12.0 | — | — |
commerceguys/addressing Version ^1.3 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.