The project has clear documentation, an MIT license, release notes, and organization backing. Its small audience and missing security policy leave less independent assurance.
68%
Total Score
75
94
50
A post-autoload-dump lifecycle script runs during installation; this is common Composer behavior but adds execution during dependency installation.
There were no commits and no active maintainers in the last three months, a meaningful sign that development activity has recently stalled despite the release history.
Five stars and two forks indicate a small user and contributor footprint, which provides limited external validation but is not by itself evidence of poor quality.
No repository security policy was found, reducing transparency about how vulnerabilities are reported and handled.
All 15 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The cache-poisoning finding is low confidence and is treated as hygiene rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/workflow Version ^6.4||^7.0 | — | — |
livewire/livewire Version ^3.0 || ^4.0 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
cleaniquecoders/traitify Version ^1.2.1 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.