Clear documentation, tests, licensing, and a security policy make the package straightforward to evaluate. Its small release history and unpinned workflow actions leave maintenance and build-reproducibility concerns.
62%
Total Score
50
100
89
100
The package is associated with a personal repository owner rather than an organization, so the single registry maintainer does not have visible organizational backing to compensate for the limited activity.
The package has only two releases, both within about six days, and none in the last 12 months despite being about 18 months old; this suggests limited ongoing maintenance.
The repository has zero stars, forks, and watchers, offering no supporting evidence of community adoption; this is a secondary concern rather than proof of poor quality.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but both action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^6.0|^7.0|^8.0|^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.