A clear MIT license, README, release notes, and repository security policy improve transparency. CI is present, but its container image is unpinned and the project has little visible adoption.
40%
Total Score
50
79
75
The package has had no releases in the last 12 months, and its latest release was on April 14, 2022. This long release gap is strong evidence of abandonment risk despite the earlier rapid release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the absence of current maintenance activity.
The package includes a substantial README, changelog, repository tests, and release notes for this version. However, the README explicitly says the test suite is incomplete, which limits confidence in ongoing reliability.
There were no new or closed issues or pull requests in the last month, while 8 pull requests remain open. This supports the broader picture of limited project activity.
All 8 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in the PHP CS Fixer workflow. The workflows have no untrusted checkout or script-injection findings, so this is a hygiene and reproducibility concern rather than an immediate severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/jetstream Version ^2.6 | — | — |
livewire/livewire Version ^2.10 | — | — |
maatwebsite/excel Version ^3.1 | — | — |
intervention/image Version ^2.7 | — | — |
spatie/data-transfer-object Version ^2.6|^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.