Define, sign, dispatch and log outgoing webhooks in Laravel with retries, HMAC signatures, and an optional Livewire + Flux admin UI.
68%
Total Score
75
100
94
63
Five workflows were analyzed with one pull_request_target workflow for Dependabot automation, but no untrusted checkouts or script-injection patterns were detected; the special workflow still warrants review before relying on the project’s automation.
Only two releases were published over about 100 days, with both arriving within roughly 17 hours; this is a young project with limited evidence of a sustained release pattern.
The repository recorded zero commits and zero active maintainers over the last three months. For a package this new, that is a meaningful maintenance concern, even though the repository is not archived.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a package that handles outgoing webhook credentials and delivery behavior.
Three workflows request top-level write permissions and two omit top-level permissions entirely, indicating weaker-than-ideal CI permission hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.