Median and percentile for Eloquent / Laravel
67%
Total Score
50
75
67
Only two releases have been published, with none in the last 12 months and the latest release about 2 years and 2 months ago. Recent repository activity partly offsets this, but the release cadence remains slow.
All one recent commit came from a single contributor, so maintenance depends entirely on one person. The repository is user-owned rather than organization-backed, providing no shown handoff capacity.
The repository has no security policy. This is a transparency and maintenance gap, although it does not by itself show that the package is unsafe.
Version v0.2.0 is a normal, non-prerelease release, though it remains below a stable major version. This is a modest maturity limitation rather than a severe concern.
The workflow audit completed cleanly with no untrusted checkouts, injection findings, or high-severity issues, but all 5 analyzed action references are unpinned. That leaves avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version >= 10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.