The repository has complete tests, release notes, and a clear README, while its workflows use unpinned actions and broad write permissions. No security policy or scanning is present, so future changes would be harder to assess.
62%
Total Score
50
100
88
83
The repository recorded zero commits and zero active maintainers in the last three months, a significant warning for a package only 129 days old.
The package is young at 129 days and has four releases, but its latest release was 129 days ago, leaving limited evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear for adopters.
All four analyzed action references are unpinned, and two of three workflows grant top-level write permissions; no dangerous triggers or audit findings were detected, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
whilesmart/eloquent-contacts Version ^1.0 | — | — |
whilesmart/eloquent-owner-access Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.