New Laravel project setup.
56%
Total Score
50
88
50
The package has had 24 releases, but none in the last 12 months; the latest release was about 16 months ago. This is a meaningful maintenance concern for a young package.
There were no commits and no active maintainers in the last three months. The repository is not archived, but this recent inactivity raises abandonment risk.
The repository has zero stars and forks and one watcher. Popularity is supporting evidence only, but this very small footprint provides little external evidence of maturity.
No security policy was found, leaving vulnerability-reporting guidance unclear for a package that changes Laravel project behavior.
All 14 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene and workflow-safety concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version ^0.1.18|^0.2.0|^0.3.0 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
godruoyi/php-snowflake Version ^3.1 | — | — |
jiannei/laravel-response Version ^6.0 | — | — |
spatie/laravel-package-tools Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.