Usable with caveats: the release is well documented, tested, licensed, and backed by an active organization, with a current release and four merged pull requests recently. However, no commits or active maintainers were recorded in the last three months, and the project has only three releases overall.
72%
Total Score
75
100
94
80
One workflow uses pull_request_target, which warrants care because that workflow class can expose elevated automation privileges, although no untrusted checkout or script injection was detected.
The package is about 20 months old but has only three releases, with one release in the last 12 months and a median interval of about 309 days; this suggests a slow maintenance cadence.
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful maintenance concern despite the recent release and pull-request activity.
Two of three workflows request top-level write permissions and one lacks top-level permissions, leaving some automation privilege broader or less explicit than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
laravel/framework Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.