Workflow images are unpinned, and the repository lacks a security policy. The MIT licensing, tests, documented release, and organization backing provide useful safeguards, but the package has seen no registry release for about five years.
56%
Total Score
75
50
89
83
The package has only one release, published about five years ago, with no releases in the last 12 months. That is strong evidence of a stagnant release line, although the linked repository was pushed more recently.
The package declares 149 runtime dependencies, an unusually broad dependency surface that increases coupling, update burden, and exposure to upstream changes. Its stated purpose explains the breadth, but does not remove the maintenance cost.
The repository recorded zero commits and zero active maintainers in the last three months. A recent push timestamp partly offsets this, but the current activity measure still indicates limited ongoing development.
There are no open issues or pull requests and no activity in the last month. This is not inherently negative, but it provides little evidence of active community maintenance.
No repository security policy is present. This is a transparency and response-process gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/dns Version ^1.6 | — | — |
spatie/ssh Version ^1.6 | — | — |
spatie/sun Version ^1.1 | — | — |
spatie/url Version ^1.3 | — | — |
spatie/enum Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.