The package has a clear README, repository tests, and a steady release history. Its single active contributor, absent security policy, and unpinned workflow image leave meaningful maintenance and build-hygiene risk.
72%
Total Score
83
94
50
All 3 recent commits came from one contributor, so maintenance depends on a single active developer. Organization ownership provides some handoff capacity, but no second recent contributor is shown.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy. For a library, this weakens vulnerability-reporting transparency, although it does not by itself show unsafe code or poor maintenance.
The audit analyzed both workflows completely and found one high-confidence, high-severity unpinned container image; all 3 action references are unpinned. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is build hygiene risk rather than a severe standalone dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
konekt/concord Version ^1.16 | — | — |
laravel/framework Version ^12.61.1|^13.12 | — | — |
cviebrock/eloquent-sluggable Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.