Healthy and suitable to depend on. It has a six-year release history, eight releases in the last year, current repository activity, and comprehensive repository tests, though maintenance is concentrated in one contributor and the repository lacks security-policy and explicit workflow permission settings.
82%
Total Score
75
100
94
80
All 4 recent commits came from one contributor, creating a genuine single-maintainer continuity risk; the repository is user-owned rather than organization-backed, so there is no provided organizational compensation.
The repository recorded 4 commits in the last 3 months, showing recent activity, but all activity came from one active maintainer.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency and maintenance gap rather than evidence of an unsafe release on its own.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The only workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege settings would provide better assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.