Clear documentation, repository tests, an MIT license, and organization backing support adoption. High-confidence workflow findings and the single-publisher setup add maintenance and release-process concerns. Pin this version rather than assuming ongoing updates.
52%
Total Score
75
94
75
The package runs a post-autoload-dump install-time script. Composer lifecycle code increases installation trust requirements, but this signal does not show that the script is unsafe.
The package has only 3 releases, all within about 10 days, and none in the last 12 months despite being about 18 months old. This suggests a stalled release cadence.
The repository recorded 0 commits and 0 active maintainers over the last 3 months. This is a concrete sign that maintenance may have stalled, even though the repository is not archived.
The audit analyzed all 5 workflows and found high-confidence bot-condition and unpinned-container-image issues, with all 11 action references unpinned and 3 workflows using top-level write permissions. These weaken build-process reproducibility and workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/testing Version ^12.0 | — | — |
symfony/dom-crawler Version ^7.2 | — | — |
illuminate/contracts Version ^12.0 | — | — |
symfony/css-selector Version ^7.2 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.