It has a clear MIT license, tests, a useful README, and a modest dependency set. Workflow references are not pinned and one action is archived, while the project lacks a security policy.
58%
Total Score
50
100
94
67
The package and repository are owned by the same individual account, so the registry and source ownership align, but there is no organization backing shown.
The package has 9 releases, but none in the last 12 months; its latest release was over a year ago, which raises maintenance and abandonment concerns.
There were no commits and no active maintainers in the last 3 months, indicating that active development has currently stopped.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
All 6 workflow action references are unpinned, and the audit found one high-confidence archived action; both weaken build reproducibility, although no untrusted checkout or script-injection path was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kalnoy/nestedset Version ^6.0 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
spatie/eloquent-sortable Version ^4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.