Install-time scripts and unpinned workflow actions add maintenance and build-integrity work. Tests, a matching README, and an active repository link provide useful context, but the project remains immature.
43%
Total Score
0
72
50
Only two releases were published, both about two days apart, and there have been no releases in the last 12 months despite the package being about 500 days old. This is strong evidence of stalled maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent releases. This materially raises abandonment risk.
The package runs four install or update lifecycle scripts, increasing installation complexity and the amount of code executed automatically. Such scripts can be normal for a Laravel starter kit, but they still add maintenance and supply-chain exposure.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external maintenance signal to offset the stalled activity.
The project uses Composer and Make, which supports reproducible project operations, but it has no reported security scanning tools. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/octane Version ^2.9 | — | — |
laravel/tinker Version ^2.10.1 | — | — |
laravel/cashier Version ^15.6 | — | — |
tightenco/ziggy Version ^2.4 | — | — |
filament/filament Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.