This is my package laravel-users
52%
Total Score
caution
Zero repository commits in three months despite 187 releases, plus an unsafe Dependabot workflow, raises maintenance risk.
The package defines a post-autoload-dump lifecycle script. This deserves awareness because installation executes package code, but the signal alone does not show unsafe behavior.
The package published 187 releases in 12 months, with a median interval of about 48 minutes. This shows strong publishing activity but an unusually noisy cadence that reduces release transparency.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance concern, even though registry releases continued during the period.
The repository has no SECURITY.md or other declared security policy. This weakens vulnerability-reporting transparency for a package handling authentication and permissions.
All 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene and workflow-safety concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version >=10.0 | — | — |
spatie/laravel-permission Version >=6.0 | — | — |
lorisleiva/laravel-actions Version >=2.8 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.