The package has clear documentation, a license, repository tests, and strong recent commit activity. Workflow permissions and an automated-merge check need attention, while no security policy limits transparency.
72%
Total Score
100
100
50
No repository security policy was found. For a package handling inventory, orders, payments, and API keys, this is a transparency gap for reporting and handling security issues.
All 13 analyzed action references are unpinned, four workflows grant top-level write permissions, and a high-confidence audit finding reports spoofable actor checks in the Dependabot auto-merge workflow. The audit was complete, but these workflow practices lower supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
centrex/tallui Version * | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
livewire/livewire Version ^4.2 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.