Testing, licensing, and release notes improve day-to-day confidence. Recent repository activity is currently quiet, and workflow dependencies are unpinned; organization backing helps offset that.
68%
Total Score
67
100
100
50
A post-create-project-cmd script runs during installation, adding behavior that consumers should understand beyond ordinary dependency loading.
There were no commits and no active maintainers in the last three months, a meaningful maintenance concern, although the package released in May and the repository was pushed in August.
No issues or pull requests were opened, closed, or merged in the last month, consistent with limited recent project activity but not sufficient alone to show abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; its organizational ownership provides some compensating project backing but not a documented process.
The single workflow was fully analyzed with no dangerous findings, but both of its action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.