The linked project is maintained and has a clear release history, with two active contributors and recent release notes. Migrate to dragon-code/laravel-actions instead of adding this abandoned package name to new projects.
22%
Total Score
100
100
89
83
Packagist marks the entire package as abandoned and names dragon-code/laravel-actions as its replacement. This is a severe dependency-lifecycle risk despite the repository still receiving maintenance.
No security policy is present in the repository, leaving vulnerability-reporting guidance unclear. This is a transparency gap, but it does not outweigh the explicit deprecation by itself.
All six workflows were analyzed with no injection or high-severity findings, but all 17 action references are unpinned and three workflows grant top-level write permissions. These are workflow hygiene concerns without an untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version >=0.1 | — | — |
laravel/framework Version ^11.0 || ^12.0 || ^13.0 | — | — |
dragon-code/support Version ^6.6 | — | — |
spatie/laravel-data Version ^4.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.