Tests, a stable release, and an MIT license provide a sound starting point. However, the repository has had no commits for about eight months, and its workflows use five unpinned actions. The repository also does not name or document this package clearly.
60%
Total Score
50
83
50
The package is about 241 days old with three releases, all published within roughly 18 hours in January; this shows an initial launch but little release history afterward.
There were zero commits and zero active maintainers in the last three months, while the repository was last pushed about eight months ago; this is meaningful evidence of stalled maintenance.
The repository name does not match the package name and its README does not mention the package, so the package-to-source relationship is not clearly documented.
The repository has no security policy, which weakens vulnerability-reporting transparency for a web application starter kit.
Both workflows were analyzed successfully with no dangerous audit findings, but all five referenced actions are unpinned and one workflow grants top-level write permissions, leaving avoidable supply-chain and token-scope exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^2.10.1 | — | — |
laravel/fortify Version ^1.30 | — | — |
laravel/framework Version ^12.0 | — | — |
laravel/wayfinder Version ^0.1.9 | — | — |
inertiajs/inertia-laravel Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.