A single maintainer and no security policy leave less backup and disclosure structure. Regular releases, a clear README, repository tests, and matching source ownership provide useful support despite the workflow hygiene issues.
60%
Total Score
50
100
75
Only one registry account can publish releases, leaving limited publishing redundancy; the repository is also user-owned rather than organization-backed.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign that current maintenance may have slowed despite earlier releases.
The repository has no security policy, reducing clarity about vulnerability reporting and disclosure handling.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. Several workflows also grant top-level write access, though no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-rdap Version ^1.3 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-health Version ^1.34 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.