The repository includes tests, a license, and a security policy, which support transparency and maintainability. Its workflows use an unpinned container image, adding avoidable build-supply-chain hygiene risk.
42%
Total Score
50
75
100
The latest release was published on October 24, 2022, and there were no releases in the last 12 months. This is strong evidence of stalled maintenance for a package still being considered for adoption.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the nearly four-year release gap. No newer activity is provided to offset the abandonment concern.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these values provide no community signal to compensate for the lack of recent maintenance.
All four analyzed action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image in the PHP code-style workflow. The workflows otherwise had no untrusted checkout or script-injection findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^8.37|^9.0 | — | — |
spatie/laravel-package-tools Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.