It has a clear MIT license, a substantial README, focused dependencies, and repository tests. All five workflow actions are unpinned and no security policy is present, but the project has recent release notes and a matching source repository.
78%
Total Score
50
100
94
83
There were no commits or active maintainers in the preceding three months, which is a maintenance caution. However, the repository was pushed for this release and the release history shows five releases in the last year, partly compensating for the short-term lull.
Composer is used for builds, but no security scanning tool was detected. The missing scanning is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a documentation gap, not a direct indication that the release is unsafe to depend on.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or write-wide permissions. However, all five referenced actions are unpinned, leaving workflow dependencies exposed to mutable upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version ^13.0 | — | — |
staudenmeir/eloquent-has-many-deep-contracts Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.