A flexible suspension and banning system for Laravel with pluggable strategies and resolvers
58%
Total Score
caution
Usable with caveats: maintenance has gone quiet and all workflow actions are unpinned.
The repository is owned by an individual user rather than an organization, so the single registry maintainer is consistent with the observed project backing but leaves a thin apparent ownership base.
The package has four releases, concentrated over roughly two weeks with a median interval of about 23 hours, but no release since 2026-03-18—around six months ago. This early burst followed by a long pause raises maintenance uncertainty.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the last push around six months ago, this is meaningful evidence of currently quiet maintenance.
The repository uses Composer and just for build work, but no security-scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence of abandonment.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, and it does not use broad top-level write permissions. However, all 8 action references are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0 || ^12.0 || ^13.0 | — | — |
cline/variable-keys Version ^2.0.1 | — | — |
facade/ignition-contracts Version ^1.0.2 | — | — |
spatie/laravel-package-tools Version ^1.93.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.