The repository includes tests, release notes, security guidance, and automated checks. All 11 workflow actions are unpinned, so builds depend on moving action references; the project also has no maintenance history beyond today.
68%
Total Score
75
100
94
83
The package runs a post-autoload-dump script during installation. This is a meaningful install-time behavior that deserves review, though the package's documented service-provider setup provides some context for it.
This is the package's only release, published today, so there is no observed history of maintenance, compatibility fixes, or release stability. The repository's quality signals partly offset the lack of track record but cannot replace it.
The repository has no commits or active maintainers recorded over the last three months. Because the project was released today, this is chiefly a lack of history rather than evidence of a collapsed mature project.
All five workflows were analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 11 referenced actions are unpinned, and one workflow grants top-level write permissions, creating avoidable build-integrity and token-scope weaknesses.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^4.0 || ^5.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.