This release appears healthy and suitable to depend on: it has a clear license, stable non-prerelease versioning, 31 releases over 637 days with 17 in the last 12 months, recent repository activity, five active contributors, and organization backing. The package is small and purpose-specific, so its limited file tree and lack of packaged tests or changelog are modest transparency gaps rather than strong abandonment indicators. The main cautions are the absence of a security policy and explicit top-level workflow token permissions, although the analyzed workflows show no dangerous trigger, checkout, or script-injection patterns.
88%
Total Score
100
100
89
80
A 1,458-character README documents installation, features, and usage, but neither the artifact nor repository contains tests or a changelog. For this small policy package, the missing tests and changelog are a modest transparency gap, partially offset by active releases and GitHub Releases usage.
The repository has only 1 star and 0 forks, indicating limited public adoption. Popularity is supporting evidence rather than a verdict, and the low counts are outweighed by recent release and contributor activity.
The repository has no SECURITY.md or other security policy. This is a genuine disclosure and maintenance gap, though it is not evidence that the package is abandoned.
All 4 workflows lack top-level token permissions declarations, leaving permissions less explicit than recommended. However, none declares top-level write access, so this is a hygiene caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-csp Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.