A clear license, matching repository, and security tooling provide useful transparency. Workflow references are not pinned, and the broad runtime dependency set increases maintenance burden.
52%
Total Score
50
50
83
75
The package has had 7 releases since July 2020 but none in the last 12 months, with the latest release in September 2020. This is a substantial maintenance concern, although the repository was pushed more recently.
The package declares 16 runtime dependencies, including several storage integrations and Laravel components. This broad dependency surface raises compatibility and maintenance burden compared with a narrowly scoped package.
There were 0 commits and 0 active maintainers in the last 3 months, indicating little recent development activity. The repository is not abandoned outright because its last push was in November 2025, but current activity remains weak.
All 8 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image. There are no untrusted checkouts or script-injection findings, so this is workflow hygiene risk rather than a severe dependency-health failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fideloper/proxy Version >=4.0 | — | — |
league/pipeline Version * | — | — |
league/flysystem Version * | — | — |
laravel/framework Version ^7.0 || ^8.0 | — | — |
intervention/image Version >=2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.