The package is well documented, licensed, and backed by repository tests, release notes, and recent commits. Pin v0.1.0 and expect early-project churn while its single maintainer and CI controls mature.
58%
Total Score
75
88
50
This is a very young package, 54 days old, with only one release and no established release interval. That limits evidence of sustained maintenance.
All two recent commits came from one contributor, leaving maintenance highly dependent on a single person. The repository is user-owned, so no organizational handoff evidence compensates for that concentration.
The repository has no security policy, which weakens vulnerability-reporting transparency for a package handling authentication, reports, screenshots, and videos.
v0.1.0 is not a stable major release, and the release notes explicitly describe it as an alpha release not safe for production. This indicates a meaningful maturity risk.
The audit found a high-confidence bot-conditions issue in a pull_request_target workflow, alongside all 9 action references being unpinned and three workflows granting top-level write permissions. No untrusted checkout or script injection was found, so this is a CI hygiene and supply-chain caution rather than a standalone severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.1 | — | — |
ezyang/htmlpurifier Version ^4.19 | — | — |
illuminate/database Version ^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.