MIT licensing, repository tests, and a complete workflow audit provide useful baseline transparency. Unpinned actions, no security policy, and the repository's limited visible activity make ongoing maintenance and build hygiene less certain.
52%
Total Score
50
100
81
50
Composer lifecycle scripts are present, including post-create-project-cmd and post-autoload-dump; these are normal for a Laravel starter kit but add install-time behavior that adopters should understand.
This is the only release, published about eight months ago, so there is little release history to demonstrate maturity or sustained maintenance.
The repository recorded zero commits and zero active maintainers in the past three months; combined with the roughly eight-month-old last push, this raises maintenance and abandonment concerns.
The repository name does not match the package name and its README does not mention the package, which creates uncertainty that this repository is the package's intended source.
Composer is used for builds, but no security-scanning tool was detected, leaving an avoidable gap in automated security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
livewire/flux Version ^2.9.0 | — | — |
laravel/tinker Version ^2.10.1 | — | — |
laravel/fortify Version ^1.30 | — | — |
laravel/horizon Version ^5.43 | — | — |
laravel/framework Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.