The project has no security policy, and its workflows leave most action references unpinned while inheriting secrets. Tests, changelog, release notes, and a matching organization repository provide useful transparency.
58%
Total Score
67
90
50
The package has 93 releases since September 2022, but none in the last 12 months and its latest release was about 20 months ago. This materially raises maintenance and abandonment concerns.
The repository recorded zero commits and zero active maintainers in the last 3 months, despite the repository not being archived. That is strong evidence of currently inactive development.
There are 48 open issues, with one new issue and no issues or pull requests closed in the last month. This suggests a backlog with limited visible response activity.
The linked repository has no security policy. For a Laravel framework extension, this reduces transparency around vulnerability reporting and response.
All 10 analyzed action references are unpinned, and high-confidence medium-severity findings show workflows inheriting secrets. No untrusted checkout or script-injection paths were found, which limits the risk but does not remove the workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2 | ^3 | — | — |
psr/simple-cache Version ^3.0 | — | — |
laravel/framework Version ^9 | — | — |
h4kuna/serialize-polyfill Version ^0.2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.