The MIT license, README, repository tests, and release notes provide useful transparency. Its single old release and extended inactivity make long-term maintenance uncertain; workflow hygiene also needs attention.
44%
Total Score
50
75
50
This is the package's only release, published nearly 3 years ago, with no releases in the last 12 months. That leaves little evidence of sustained maintenance.
There were no commits and no active maintainers in the last 3 months, consistent with a project that has been inactive for an extended period. This materially increases abandonment risk.
The linked repository has no security policy, leaving no documented reporting path for vulnerabilities. This is a transparency and maintenance gap.
The release is v0.1.0 rather than a stable major version, so the API and project direction may still change. Its non-prerelease label offers limited compensation.
All 12 analyzed action references are unpinned, and three workflows grant top-level write permissions. The audit also found a high-confidence bot-condition issue in the Dependabot auto-merge workflow, though no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.