Clear documentation, tests, and licensing reduce integration friction. The project is still very new, with no commits since its first release and workflow hygiene gaps; pin this version only if that limited track record fits your needs.
67%
Total Score
75
100
88
75
This package has only one release, published 99 days ago, so there is not yet enough history to establish a dependable maintenance cadence.
There were zero commits and zero active maintainers in the last three months. Because the package is only 99 days old, this is an early maintenance warning rather than proof of abandonment.
The repository uses Make and Composer build tooling, but no security scanning tools are reported, leaving a modest transparency and hygiene gap.
The repository has no security policy. This does not show a defect in the package, but it gives maintainers and consumers no documented vulnerability-reporting path.
All four workflows were analyzed, with no untrusted checkout or script-injection findings, but all six action references are unpinned and a high-confidence audit found an ad hoc package installation. Two release workflows also grant top-level write permissions, adding avoidable workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
whilesmart/eloquent-invoices Version ^1.0 | — | — |
whilesmart/eloquent-owner-access Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.