Healthy and reasonable to use, with routine operational caveats. It has active recent development, tests, clear licensing, and organization backing; the main gaps are limited adoption and missing repository security documentation.
82%
Total Score
100
100
89
80
The repository has only one star and no forks or watchers, so external adoption and community validation are limited. This is a supporting caution rather than a maintenance verdict because recent commits, tests, and organization backing are present.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency and maintenance gap, though it does not by itself make the package unfit to use.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a genuine transparency gap for a package that handles YouTrack tokens and webhooks.
The sole GitHub Actions workflow has no top-level token permissions declaration. Although it requests no top-level write access, explicitly restricting permissions would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/console Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.