This is a healthy, actively maintained release with a clear MIT license, repository-backed source, tests, CI workflows, dependency scanning, and a stable v2.0.0 release profile. The package is still relatively young and has modest activity and no observed community popularity, while the repository lacks a security policy and explicit top-level GitHub Actions permissions; these are real hygiene gaps but are outweighed by recent publishing, a non-archived organization-owned repository, two active contributors with balanced commit share, and six merged pull requests in the last month.
82%
Total Score
100
100
89
80
The package is young at 177 days with five releases, including a release within minutes of collection and a median interval of about 30 days; this shows ongoing delivery but limited long-term history.
The repository has zero stars, forks, and watchers, which provides no external adoption evidence; this is a caution for maturity assessment but is not decisive for a small, organization-owned package.
No repository security policy was found, leaving vulnerability reporting and response guidance undocumented.
All four workflows lack top-level permissions declarations. Although none grants top-level write access, explicitly declaring least-privilege permissions would improve CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
roots/acorn Version ^5.0 | — | — |
yard/acf-registrar Version ^2.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.