The repository includes tests, a changelog, security scanning, and release notes for this version. Organization backing and a small dependency surface help, but the package still needs careful identity and workflow review.
48%
Total Score
75
100
83
75
The package is reported to borrow the identity of the much more established spatie/ray, with borrows_lookalike_identity true. Although artifact overlap is only 0.2, this creates a serious risk that consumers intended to install spatie/ray instead.
The package has existed for about five years with 9 releases, but only 1 release in the last 12 months and a median interval of about 188 days indicate a slow cadence. The latest release is recent enough to show the project is not abandoned.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This suggests limited recent development activity, although the release history and repository push data provide some evidence of ongoing maintenance.
No security policy was found in the repository, reducing the project's transparency for reporting vulnerabilities. Psalm scanning and the repository's tests provide partial compensating evidence.
All 13 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in php-cs-fixer.yml. No untrusted checkouts or script injection were found, so this is a workflow hygiene concern rather than proof of compromise.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/collections Version ^10|^11.43.2|^12|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.