The package is documented, licensed, tested in its repository, and backed by an organization with security tooling. Pin 0.1.1 and account for the stale maintenance and workflow hygiene before adopting it.
52%
Total Score
100
100
81
100
Only two releases were published, with the latest in August 2022 and none in the last 12 months. This is a meaningful maintenance concern for a dependency, though the small scope may reduce the need for frequent releases.
The linked repository is active rather than archived, but its last push was in October 2023, which is consistent with the separate evidence of stalled recent maintenance.
Version 0.1.1 is not a stable major release, so compatibility guarantees are weaker, although it is not marked as a prerelease.
The audit analyzed all five workflows without failures, but found high-confidence bot-condition and unpinned-container-image issues, and all 11 action references are unpinned. These are workflow supply-chain hygiene risks, although no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.53 | — | — |
spatie/data-transfer-object Version ^3.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.