The repository is well matched to the package and includes a license, tests, a changelog, release notes, and automated security tooling. Organization backing is reassuring, but pinning this exact version limits exposure to future changes.
58%
Total Score
75
94
67
The package has 22 releases since September 2022, but none in the last two years; the latest release was in May 2024. This is a meaningful maintenance concern for a toolkit with ongoing dependencies.
The repository had 0 commits and 0 active maintainers in the last three months, consistent with the long release gap. The project is not archived, but current maintenance activity is absent.
The repository has no published security policy. This is a transparency and vulnerability-reporting gap, though Dependabot scanning provides some compensating security tooling.
All 6 action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
linfo/linfo Version ^4.0.7 | — | — |
composer/composer Version ^2.4.2 | — | — |
czproject/git-php Version ^4.0.5 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.