The MIT license, repository tests, and release notes provide useful transparency. The workflow audit found no dangerous patterns, though its three action references are unpinned.
8%
Total Score
0
50
50
The package is marked abandoned on Packagist, with Laravel's framework named as the replacement. This directly indicates that new projects should not depend on this release.
The package has 34 releases over more than 10 years, but none in the last 12 months and its latest release was in September 2023. The historical cadence is outweighed by the current stoppage.
The repository recorded zero commits and zero active maintainers in the last three months. This supports the abandonment concern rather than showing merely slower development.
The linked repository is archived, confirming that it is no longer intended for ongoing maintenance. Its last push was in September 2023.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all three action references are unpinned, leaving a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8.0 || ^9.0 || ^10.0 < 10.23.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.