Recent commit activity is absent, and the workflows use unpinned actions and images. Licensing, tests, release notes, and organizational backing provide useful counterweight.
45%
Total Score
75
86
75
The package is flagged as borrowing the identity of the much more downloaded spatie/laravel-data, with borrows_lookalike_identity true. Although artifact overlap is zero and the repository matches this package, the identity signal remains a serious adoption risk.
The repository recorded zero commits and zero active maintainers in the last 3 months. A recent push exists in repository_archived, but the provided activity window still shows no demonstrated ongoing development.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. The package's clear repository and license provide some broader project transparency but do not replace this process.
All 7 action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image in php-cs-fixer.yml. No untrusted checkouts or script injection were found, limiting the concern to workflow supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
symfony/dom-crawler Version ^4.0|^5.0|^6.0|^7.0|^8.0 | — | — |
symfony/css-selector Version ^4.0|^5.0|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.