Documentation and project structure are clear, with repository tests, MIT licensing, and no install-time scripts. Its workflow still uses unpinned actions and has no published security policy.
44%
Total Score
0
86
67
The latest release was about 5 years ago, and there have been no releases in the last 12 months. Sixteen releases show some initial development, but the long silence raises abandonment risk.
The repository recorded no commits and no active maintainers during the last 3 months, consistent with the package having been inactive for about 5 years.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This matters for a client handling accounting-service integrations.
All 4 analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene. The audit found no untrusted checkouts, script injection, or high-severity findings, limiting this to a caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.26.3|^2.0 | — | — |
illuminate/http Version ~5.5|~6|~7|~8 | — | — |
illuminate/routing Version ~5.5|~6|~7|~8 | — | — |
illuminate/database Version ~5.5|~6|~7|~8 | — | — |
quickbooks/v3-php-sdk Version ^5.3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.