All six workflow actions are unpinned and no security policy is published. The package is licensed, documented, and its latest release has release notes.
67%
Total Score
50
92
75
The project has existed for about 4 years and 5 months with 31 releases, but only 1 release appeared in the last 12 months. The latest release is recent, so this is a modest cadence concern rather than evidence of abandonment.
The repository recorded 0 commits and 0 active maintainers in the last three months, which raises a maintenance and abandonment concern. The release published during this period provides some evidence of recent activity but does not establish ongoing maintenance.
There were no new or closed issues and no merged pull requests in the last month, alongside 9 open issues and 6 open pull requests. This supports concern about responsiveness, although the latest release shows the project is not entirely inactive.
No security policy was found in the repository, leaving vulnerability reporting and response expectations unclear. Dependabot scanning provides some compensating security practice but does not replace a published policy.
All 6 analyzed action references are unpinned, reducing build reproducibility and increasing exposure to action changes. The audit found no untrusted checkouts, script injection, write-wide permissions, or other high-confidence workflow findings.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.0 || ^4.0 | — | — |
stepanenko3/laravel-helpers Version ^1.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.