No commits were recorded in the last three months, and the workflow audit found a high-confidence bot-condition issue plus entirely unpinned actions. The matching repository, tests, license, README, and security tooling provide useful transparency.
55%
Total Score
50
83
50
The package has only one release, published about 3 years and 9 months ago, with no releases in the last 12 months. A recent repository push partly offsets this, but registry maintenance is still weak.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This suggests current maintenance may be inactive despite the repository not being archived.
The linked repository has no security policy. This reduces vulnerability-reporting transparency, though Dependabot provides some compensating security tooling.
Version 0.1 is not a stable major release, which signals limited maturity. It is not marked as a prerelease, so the concern is moderate rather than severe.
All 12 analyzed action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull request trigger has no untrusted checkout or script-injection sink, limiting the impact to workflow hygiene and maintenance risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.64 | — | — |
illuminate/contracts Version ^9.0 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.