Healthy and suitable to depend on. It has a recent stable release, active repository maintenance, clear licensing, tests in the source repository, and organizational backing; workflow permission gaps and the absence of a security policy are minor caveats.
88%
Total Score
100
100
100
70
One of four workflows uses pull_request_target for Dependabot auto-merge, which deserves review because that trigger can expose elevated workflow context. However, no untrusted checkouts or script-injection patterns were detected.
The repository has no SECURITY.md or other detected security policy. This is a transparency gap, although the package does use Dependabot and the absence does not by itself indicate abandonment.
Three of four workflows lack top-level permission declarations, and one workflow grants top-level write access. Explicit least-privilege declarations would improve repository hygiene, though this concerns project automation rather than normal package use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/packagist-api Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.