Documentation, tests, a license, and a small runtime dependency set make integration clearer. The project is less than a day old, and its workflow inherits secrets and uses an unpinned action.
70%
Total Score
50
100
93
83
The repository is owned by an individual rather than an organization, so the single registry maintainer reflects a genuinely thin ownership base. The linked repository and package identity are consistent, partially reducing that concern.
This release is part of a package published less than a day ago, with four releases in that period. The rapid initial releases show activity but provide no meaningful long-term maintenance history.
There were no commits or active maintainers in the preceding three months, but the repository was pushed less than an hour ago and the package itself is less than a day old. The short history limits confidence rather than proving abandonment.
The only workflow was fully analyzed and has no untrusted checkout or script-injection findings, but it inherits secrets with high-confidence medium severity and uses its only action without pinning. It lacks a top-level permissions block, which is acceptable on its own but provides less explicit permission control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.