The package includes a clear MIT license, a substantial README, tests, and release notes for this version. Its one workflow uses four unpinned actions, including an archived action, and the repository has no security policy.
62%
Total Score
50
100
94
50
One registry maintainer is consistent with a user-owned project, but it leaves a thin publishing base. Recent repository evidence partly offsets this capacity concern.
The repository is owned by an individual rather than an organization, so there is no organizational backing to compensate for the single registry maintainer. The repository is correctly linked to the package.
The package has 22 releases since July 2020, but none in the last 12 months and its latest release was in December 2024. This indicates a meaningful maintenance slowdown.
There were no commits and no active maintainers in the last three months. Although the repository was pushed in February 2026, the reported development activity still suggests slow maintenance.
No SECURITY.md policy was found. This is a transparency gap, though it is less significant because the repository does use Dependabot.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
laravel/framework Version ^8.40.0 || ^9.0.0 || ^10.0.0 | — | — |
bensampo/laravel-enum Version >=3.0 <=6.0 | — | — |
spatie/data-transfer-object Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.