Clear documentation, tests, and a matching source repository help integration. The single release and no commits in three months leave maintenance uncertain, while all four workflow actions are unpinned.
64%
Total Score
50
100
94
67
The source repository is owned by an individual account rather than an organization, so the project has limited visible institutional backing.
This is the only release, published 450 days ago, with no releases in the last 12 months. That limited history makes long-term maintenance harder to establish.
There were no commits and no active maintainers in the last three months. Although the repository was pushed in October 2025, current maintenance activity is absent.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is not evidence of unsafe code by itself.
The single workflow was fully analyzed with no injection or untrusted-checkout findings, but all four action references are unpinned. That leaves the build exposed to dependency drift even without a detected workflow exploit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.