The source repository has tests, a changelog, a matching README reference, and an MIT license. Its small release history and roughly six-month pause in commits warrant pinning version 1.1.0.
62%
Total Score
75
100
88
50
Only two releases have been published since June 2025, with one release in the last 12 months and a median interval of about 261 days. This indicates limited release maturity and cadence.
The repository recorded no commits and no active maintainers during the last three months. The recent release push helps, but the absence of continuing activity raises maintenance risk.
The repository uses Composer build tooling but reports no security scanning tools. That is a modest transparency and maintenance gap, not evidence of abandonment by itself.
No security policy was found in the repository, leaving vulnerability-reporting expectations undocumented.
All three workflows were analyzed with no audit findings or untrusted execution sinks, but all seven action references are unpinned. The workflows also omit top-level permissions blocks, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pestphp/pest Version ^3.7.5|^4.0 | — | — |
illuminate/auth Version ^12.0 | — | — |
pestphp/pest-plugin Version ^3.0.0|^4.0 | — | — |
soyhuce/laravel-testing Version ^2.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.