The repository has tests, release notes, dependency scanning, and a clearly declared MIT license. GitHub workflows use unpinned actions and include a high-confidence bot-condition finding, so automation deserves review.
52%
Total Score
50
80
50
The package has had no release in about 3 years and 6 months, with zero releases in the last 12 months. That materially raises abandonment risk despite a history of 10 releases.
The repository recorded zero commits and zero active maintainers in the last 3 months. This supports the release-history concern and indicates currently inactive development.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is partly offset by the presence of Dependabot scanning.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding reports that actor context may be spoofable. The pull_request_target workflow has no untrusted checkout or script-injection findings, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^2.12 | — | — |
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.