The package has a clear MIT license, useful documentation, tests in the repository, and a stable release. However, its source has seen no recent commits, and the workflows include a high-confidence unpinned container image.
45%
Total Score
0
100
86
50
The latest release was over 3 years ago, with no releases in the past 12 months. Five releases and a prior regular cadence show some history, but the prolonged pause materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the past 3 months, consistent with the release history showing no release in over 3 years.
The repository has no security policy, leaving vulnerability reporting and maintainer response expectations undocumented. The package's other documentation does not compensate for this repository-level gap.
All 10 analyzed action references are unpinned, including a high-confidence finding for an unpinned container image in the PHP CS Fixer workflow. The audit completed fully and found no untrusted checkout or script-injection path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.