It includes a readable package guide, release notes for this version, tests in the repository, and a clear MIT license. GitHub workflows have broad write access and install an ad hoc package, but the audit found no high-confidence dangerous path.
84%
Total Score
100
100
50
The repository has no security policy, leaving reporting expectations less explicit. This is a transparency gap, but it is not severe enough to outweigh the active project evidence.
All 12 action references are unpinned, three workflows grant top-level write access, and a high-confidence low-severity finding reports an ad hoc package install. However, there are no untrusted checkouts, script injections, or high-severity findings, so this is workflow hygiene rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/laravel-screenshot Version ^1.1 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.