The package has a clear README, tests, MIT licensing, and a GitHub release for this version. Maintenance is modest rather than strong, with one release in the last 12 months, no commits in the last three months, no security policy, and unpinned workflow actions.
73%
Total Score
83
100
88
75
The package has seven releases over about 3 years and one release in the last 12 months, with a median interval of about 189 days. This indicates modest, not highly active, maintenance.
There were zero commits and zero active maintainers in the last three months. The recent release partly offsets this, but the current maintenance signal remains thin.
Composer build tooling is present, but no security scanning tools were detected. This is a moderate transparency and assurance gap for a package that handles key and certificate-generation code.
The repository has no security policy. That weakens the documented process for reporting and handling vulnerabilities, though it does not by itself show an active security issue.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but both of its two action references are unpinned. That leaves CI dependent on mutable action versions and warrants a hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.