Repository tests, release notes, and Composer/Dependabot tooling provide useful project hygiene. Recent registry releases do not yet establish sustained maintenance, and workflow controls need attention.
58%
Total Score
50
94
50
The registry lists one publisher account. Because the repository is owned by the same individual rather than an organization, this indicates a limited maintainer base and higher bus-factor risk.
The repository recorded zero commits and zero active maintainers in the last three months. This weakens evidence of sustained maintenance despite the recent registry release.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented. This is a transparency gap for a package intended for application integration.
Version 0.2.0 is not a stable major release, so the API may still change. It is not marked as a prerelease, which partly offsets that concern.
All nine action references are unpinned, and the audit found a high-confidence, high-severity bot-conditions issue in the Dependabot auto-merge workflow. There are no untrusted checkouts or script-injection findings, but the workflow controls still warrant caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^1.0.0 | — | — |
illuminate/routing Version ^12.0||^13.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/container Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.