A Laravel Pulse card displaying PanPHP analytics
58%
Total Score
50
86
100
This is the sole release, published about 1 year 11 months ago, with no releases in the last 12 months. That makes the package's release maintenance look stale despite recent repository activity.
All recent commits came from one contributor, giving the project a concentrated maintenance base. With user-owned rather than organization-backed ownership, there is little demonstrated redundancy if that contributor stops maintaining it.
The repository recorded one commit in the last 3 months from one active maintainer. This shows some current activity, but the very low pace provides limited evidence of sustained maintenance.
Version 0.0.1 is an early, non-stable-major release, so its API and behavior may still change substantially. The GitHub release and release notes provide some transparency but do not offset the immature versioning.
The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow, and three workflows grant top-level write permissions. There are no untrusted checkouts or script-injection findings, so this is a workflow-hygiene concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
panphp/pan Version ^0.1.3 | — | — |
laravel/pulse Version ^1.2 | — | — |
illuminate/contracts Version ^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.