The source is licensed, documented, tested, and backed by an organization with matching repository references. Its registry release history is stagnant, and the package is identified as borrowing another package's identity; workflow pinning and the absent security policy add smaller concerns.
38%
Total Score
75
71
75
The package is marked as borrowing the identity of spatie/image, which has far more releases and downloads; although artifact overlap is zero, this remains a serious dependency-selection risk.
Only one release exists, with no registry release since February 2022. The repository is present, but this package-level cadence leaves consumers exposed to abandonment and compatibility risk.
There were zero commits and zero active maintainers in the three months measured, which reinforces the lack of recent package maintenance despite the repository not being archived.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. Dependabot is enabled, which provides some compensating maintenance tooling but does not replace a policy.
All eight action references are unpinned, and the audit found a high-confidence unpinned container image. The pull-request target workflow has no untrusted checkout or script-injection sink, limiting the impact to workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^3.2 | — | — |
spatie/laravel-health Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.