Risky to adopt: the package closely borrows the identity of the much more established spatie/ray without describing itself as a fork. Its release history is very short and there were no commits in the last three months, although the repository is backed by Spatie and includes tests and release notes.
42%
Total Score
88
100
85
63
The package resembles spatie/ray, has only 2 stable releases versus 124 for that package, and is marked as borrowing its identity without identifying itself as a fork. This creates a serious risk that consumers intended to install the established package instead.
One workflow uses pull_request_target for Dependabot automation, but no untrusted checkout or script-injection patterns were detected. The workflow setup is therefore a manageable concern rather than a decisive health problem.
Only 2 releases exist, both published about 5 months ago and within roughly 1 hour of each other. That provides little evidence of an established release cadence or long-term maintenance.
The repository recorded 0 commits and 0 active maintainers during the last 3 months. Although it was pushed more recently than that window, current maintenance activity is not demonstrated.
No repository security policy was found. That weakens vulnerability-reporting transparency, though the README directs users to a security policy and the repository has Dependabot scanning.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/ray Version ^1.48 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.