Clear documentation, tests, release notes, and a matching repository make integration straightforward. The workflow audit found no dangerous findings, though both action references are unpinned. No security policy is published, which is a minor transparency gap.
84%
Total Score
100
100
50
The linked repository has no security policy. This is a minor transparency gap for reporting vulnerabilities, but it is not evidence of abandonment and is partly offset by the active repository and clear release documentation.
All 1 workflow was analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of its action references are unpinned, leaving a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.0|^3.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.