The package has clear documentation, tests in the repository, a license, and recent contributions from two active contributors. Workflow hygiene needs attention, especially broad permissions, unpinned actions, and a high-confidence bot-condition finding; releases are also infrequent.
68%
Total Score
83
94
50
The package uses a post-autoload-dump install-time script. This is a mild supply-chain and installation-complexity concern, though the signal does not show a dangerous script or additional behavior.
The package has only 3 releases over 483 days, with a median interval of about 231 days. The latest release was published recently, which reduces abandonment concern but does not offset the slow overall cadence entirely.
The repository recorded 2 commits in the last 3 months, with 2 active maintainers. This is limited activity, but the recent release and active contributors provide some compensation.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear.
All 4 workflows were analyzed, but all 9 action references are unpinned, 2 workflows grant top-level write permissions, and a high-confidence bot-conditions finding was reported in the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
maatwebsite/excel Version ^3.1||^4.0 | — | — |
illuminate/support Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.