Documentation, repository tests, and a matching source repository make the package straightforward to evaluate. Its small dependency set is reasonable, but the workflow uses an unpinned container image and maintenance appears to have stopped.
42%
Total Score
0
100
67
25
The package has had only two releases, with the latest on January 7, 2022 and none in roughly 4 years 8 months. That strongly indicates abandonment risk for a Laravel integration.
There were zero commits and zero active maintainers in the last three months, after no observed recent release activity. This is strong evidence that maintenance has stopped rather than merely slowed.
All seven action references are unpinned, and the auditor found a high-confidence, high-severity unpinned container image in the PHP CS Fixer workflow. The workflows have no untrusted triggers or script-injection findings, but the release automation still has notable reproducibility and supply-chain hygiene risk.
The repository has zero stars and forks and only three watchers. Popularity alone is not decisive, but these counters provide no supporting evidence of an active user or contributor community alongside the stale activity.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported. This is a secondary concern because the stronger risk comes from the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rollbar/rollbar Version ^3.0 | — | — |
illuminate/support Version ^8.74 || ^9.0 | — | — |
illuminate/contracts Version ^8.74 || ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.