The package includes tests, a changelog, a clear MIT license, security scanning, and a security policy. Its workflow has no detected risky sinks, though its action references are not pinned.
72%
Total Score
50
100
94
88
One registry publishing account is listed, which provides a thin publishing base. The linked repository is user-owned, so there is no organization backing shown to compensate for that narrow registry maintainer list.
This is a brand-new package: all four releases appeared on the same day, so there is not yet enough history to demonstrate sustained maintenance.
The repository reports 0 commits and 0 active maintainers in the last three months. Because the package was first released today, this is an important but partly age-related maintenance gap rather than evidence of abandonment.
The sole workflow was fully analyzed and has read-only permissions, no untrusted checkouts, no script injection, and no audit findings. However, all 3 of 3 action references are unpinned, leaving avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0 | — | — |
laravel/framework Version ^13.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.