The repository has tests, release notes, matching package files, and organization backing. Maintenance has been quiet for about three months, and its two workflow actions are unpinned; there is also no published security policy.
77%
Total Score
75
100
67
The repository recorded no commits and no active maintainers during the last three months. The recent release and push partly compensate for this short quiet period, but the lack of follow-up activity is a maintenance caution.
The repository has no SECURITY.md or other published security policy. This reduces vulnerability-reporting transparency, though it does not by itself indicate abandonment.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both referenced actions are unpinned, leaving a modest reproducibility and dependency-integrity gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
incentfit/inky Version 1.3.6.5 | — | — |
illuminate/view Version ^12.55|^13.10 | — | — |
illuminate/support Version ^12.55|^13.10 | — | — |
symfony/dom-crawler Version ^7.4.12|^8.0.12 | — | — |
tijsverkoyen/css-to-inline-styles Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.