Clear documentation, tests, licensing, and a security policy provide useful transparency. Workflow issues add avoidable maintenance and publishing risk.
45%
Total Score
50
94
100
One registry maintainer is consistent with a small package, but this leaves little visible publishing capacity when combined with the absence of recent repository activity.
The latest release was about three and a half years ago, with no releases in the last 12 months. Sixteen releases show some prior history, but the current gap materially raises abandonment risk.
The repository had zero commits and zero active maintainers in the last three months, consistent with the long release gap and suggesting maintenance has stopped.
There were no new or closed issues or pull requests in the last month, while three pull requests remain open, providing no evidence of active issue resolution.
All 11 analyzed action references are unpinned, and the audit found high-confidence bot-condition and unpinned-container-image findings. The pull_request_target trigger is ordinary by itself, but these workflow gaps add supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
illuminate/contracts Version ^8.73 | ^9.0 | ^10.0 | — | — |
sawirricardo/midtrans-api Version ^1.0.10 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.