Recent releases include release notes, repository tests, a security policy, and Composer security scanning. The package is actively maintained, but its proprietary license and single-contributor ownership warrant checking rights and continuity before adoption.
66%
Total Score
67
94
88
The manifest declares a proprietary license, while license files are present in both the package and repository. This establishes licensing coverage but may restrict use in projects expecting an open-source license.
The repository is owned by a user account rather than an organization, and the repository and registry ownership align. This supports package identity but provides no organizational handoff capacity.
One contributor made 100% of the 49 recent commits. This concentrated ownership creates a meaningful continuity risk despite the strong commit volume.
The single workflow was fully analyzed, uses read-only permissions, and has no reported injection or high-severity findings. However, all 4 referenced actions are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dedoc/scramble Version ^0.13.36 | — | — |
laravel/framework Version >=13.8 <14.0 | — | — |
livewire/livewire Version ^4.3 | — | — |
bacon/bacon-qr-code Version ^3.1 | — | — |
laravel-lang/common Version ^6.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.