It includes a clear README, tests, and an MIT license. Install-time scripting and no security policy leave limited operational transparency.
64%
Total Score
67
100
86
50
A post-autoload-dump install-time script runs during Composer operations, adding some supply-chain and installation complexity even though this signal alone is not severe.
The package is 0 days old with only 3 releases, so its maintenance record and maturity are not yet established.
One contributor made all 2 recent commits. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only 2 commits were recorded in the last 3 months, which is limited evidence of sustained maintenance for a package released today.
Composer build tooling is present, but no security scanning tools were detected, leaving security-process coverage limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.