The project is only 43 days old, so its long-term stability is not yet demonstrated. Its organization backing, 36 commits in three months, release notes, tests, and documentation provide meaningful support, despite missing security policy and unpinned workflow actions.
72%
Total Score
100
100
89
75
This is a very new package, released only once and 43 days ago, so there is little release history to establish long-term maintenance consistency.
Composer build tooling is present, but no security scanning tool is reported. The missing scanner is a transparency and hygiene gap, not evidence of unsafe code by itself.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures unclear.
Both workflows use read-only permissions and the audit completed fully with no untrusted checkout or script-injection findings. However, all 13 action references are unpinned; the cache-poisoning findings are low-confidence hygiene warnings, so this lowers confidence in build reproducibility but is not a severe risk alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
artisanpack-ui/core Version ^1.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
artisanpack-ui/hooks Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.