It has a clear MIT license, a useful README, repository tests, and Dependabot scanning. All nine workflow actions are unpinned, and a high-confidence bot-condition finding adds workflow risk.
57%
Total Score
75
94
50
The package has seven releases over about two years, but only one release in the last 12 months, indicating a slow maintenance cadence rather than abandonment by itself.
There were no commits and no active maintainers in the last three months, a concrete sign that maintenance may be slowing despite the repository remaining available.
The repository has no security policy, leaving the process for reporting and handling vulnerabilities unclear.
All nine action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection findings, so this is workflow hygiene and risk rather than a severe standalone failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/ssh Version ^1.10 | — | — |
rockbuzz/lara-cwapi Version ^0.1.5 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.92.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.