This release appears reasonably healthy to depend on: it has a linked, matching repository owned by an organization, a valid MIT license, recent publication and repository activity, documented tests and changelog in the repository, security policy coverage, dependency scanning, and no deprecation or archived status. The main concerns are that it remains in the 0.x major series, all 13 recent commits came from one contributor, the artifact uses install-time lifecycle scripts, and its workflows do not declare top-level token permissions. These are meaningful maintenance and operational cautions, but they are partly offset by organizational backing, recent release activity, repository tests and changelog, and the absence of analyzed dangerous workflow patterns.
82%
Total Score
90
100
94
80
The package declares post-autoload-dump and post-install-cmd lifecycle scripts, which increase installation-time execution and review requirements even though no specific malicious behavior is indicated here.
One contributor made 100% of the 13 commits in the last three months, creating a real continuity risk; organizational ownership provides some potential handoff capacity but does not remove the observed concentration.
None of the four workflows declares top-level permissions and none declares read-only permissions; although no workflow has top-level write access, the incomplete permission hardening is a security hygiene gap.
The assessed version is not a prerelease, but it remains below 1.0, so the public API may still change and carries more compatibility uncertainty than a stable major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.