The repository has tests, a substantial README, active commits, and security scanning. Maintenance is concentrated in one contributor, and the unusually rapid release cadence plus missing security policy reduce confidence in long-term resilience.
62%
Total Score
63
100
93
83
Only one registry account has publish access. That is consistent with the linked user-owned project, but it leaves publishing and release continuity dependent on one person.
The repository is owned by a user account rather than an organization, so there is no demonstrated organizational handoff capacity to offset the concentrated maintainer base.
The package has published 102 releases in 101 days, with a median interval of about 3 hours; that unusually rapid cadence can indicate churn, although it also shows active publishing.
All 85 commits in the last 3 months came from one contributor, so maintenance and review capacity are highly concentrated.
No repository security policy was found. This is a transparency and disclosure gap, though the presence of GitGuardian scanning partly compensates.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.0|^13.0|^14.0|^15.0 | — | — |
andydefer/laravel-repository Version ^2.17.30 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.