The package includes a substantial README, repository tests, a changelog, and release notes for this version. MIT licensing, a matching repository, read-only workflow permissions, and security scanning add transparency, while the very recent history leaves long-term maintenance unproven.
72%
Total Score
75
100
89
67
Only two releases exist, both published within the same day, so the package has not yet demonstrated a sustained release pattern.
There were no commits or active maintainers in the last three months, but the repository itself is newly created and had a push immediately before assessment, so this is caution rather than abandonment evidence.
The repository has zero stars, forks, and watchers. That provides no supporting adoption evidence, although the package's same-day launch makes the lack of popularity unsurprising.
No repository security policy was found, leaving reporting and disclosure expectations undocumented for a package that processes submitted form content.
The single workflow was fully analyzed, uses read-only permissions, and has no reported audit findings, but all four action references are unpinned, weakening reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.