The source repository is not archived and matches the package, with tests and release notes for this version. However, it has had no commits for about three months, uses two unpinned workflow actions, and has no security policy.
35%
Total Score
50
79
50
Packagist marks the entire package as abandoned and names blade-sanctum-kit as its replacement. This is a substantial adoption and maintenance risk even though the repository remains available.
The package has six releases overall, but none in the last year; its latest release was about a year ago. This supports the abandonment concern, despite the initially rapid release interval.
The repository recorded no commits and no active maintainers during the last three months. That suggests maintenance has stalled, although the repository was pushed more recently than the release history indicates.
The linked repository has no security policy. For a Laravel starter kit intended to be copied into applications, this is a transparency and maintenance gap.
Both workflows were analyzed successfully with no dangerous triggers or audit findings, but all two action references are unpinned. The missing top-level permissions blocks are acceptable on their own, so this is a limited hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/breeze Version ^2.3 | — | — |
laravel/tinker Version ^2.10.1 | — | — |
laravel/framework Version ^12.0 | — | — |
laravel/telescope Version ^5.10 | — | — |
livewire/livewire Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.