Healthy and reasonable to use, with some operational caveats. It has frequent stable releases, a maintained organization-backed repository, tests and security tooling, but no commits in the last three months and several workflows lack explicit permissions.
78%
Total Score
75
100
70
One of seven workflows uses pull_request_target for Dependabot auto-merge, which warrants review because it operates with elevated workflow context. No untrusted checkouts or script-injection patterns were detected, limiting the concern.
The package runs a post-autoload-dump install-time script. This is a modest supply-chain and installation-complexity concern, though the available repository tooling provides some context for controlled maintenance.
There were no commits and no active maintainers in the last three months. This is a real maintenance concern, although the package has recent releases and a push later in the period.
Four workflows lack top-level token permissions and two declare top-level write access. Although only one workflow is explicitly read-only, this permissions posture is less restrictive than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.8 | — | — |
illuminate/contracts Version ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.19 | — | — |
codebar-ag/laravel-flysystem-cloudinary Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.