A readme, tests, MIT licensing, and a clean release audit provide useful transparency. The small repository and limited activity leave little evidence of long-term support.
63%
Total Score
50
88
50
The package is about six weeks old and has only one release, so there is little release history to demonstrate sustained maintenance.
One contributor made all commits in the last three months, leaving maintenance dependent on a single person with no demonstrated handoff capacity.
Only two commits were recorded in the last three months. That is some recent activity, but it is limited evidence of an established maintenance cadence for a new package.
The repository has no security policy, reducing transparency about how users should report vulnerabilities in a package that exposes application telemetry through an MCP server.
The sole workflow is fully analyzed and has no dangerous-trigger or injection findings, but its one action is unpinned and the workflow grants top-level write permissions, creating modest supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^0.9.3 | — | — |
laravel/framework Version ^11.45.3|^12.41.1|^13.0 | — | — |
laravel/telescope Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.