The workflow audit found a high-confidence bot-condition problem and all six action references are unpinned. The license files and repository tests are useful safeguards, but the declared MIT license conflicts with the detected Apache-2.0 license.
55%
Total Score
50
88
50
A license file is present in both the artifact and repository, but the manifest declares MIT while the detected file license is Apache-2.0. That mismatch reduces licensing clarity.
The package runs a post-autoload-dump install-time script. This adds some installation complexity, but the signal does not show a destructive or unusual action.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, indicating limited visible backing capacity.
This package has only two releases across about 22 months, with one release in the last year and an interval of about 15 months. That is sparse for a library and raises maintenance concerns.
There were no commits and no active maintainers in the last three months. Combined with the sparse release history, this points to limited recent maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
archtechx/enums Version ^1.1 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
spatie/laravel-package-tools Version ^1.30 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.