Documentation, licensing, and organization ownership are solid, with dependency scanning in place. The small project footprint and unpinned workflow actions leave limited maintenance and build-integrity margin.
61%
Total Score
75
88
75
Only two releases exist, with the latest published in September 2022 and none in roughly four years. That strongly limits evidence of ongoing maintenance, although the package may be intentionally stable.
The repository recorded zero commits and zero active maintainers in the last three months, while its last push was in October 2023. This is meaningful abandonment risk despite the repository remaining available.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. The README does provide a security-vulnerability section, which partly offsets the missing formal policy.
All five analyzed action references are unpinned, which weakens build reproducibility and action supply-chain hygiene. The audit found no untrusted checkouts, script injection, or elevated top-level write permissions, so this is a caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spiral/boot Version ^3.0 | — | — |
spatie/ignition Version ^1.2 | — | — |
spiral/exceptions Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.