Its documentation and release notes are strong, with repository tests and a changelog supporting maintenance quality. Workflow pinning and the missing security policy leave modest transparency and build-hygiene concerns.
84%
Total Score
100
100
94
50
A post-autoload-dump install-time script is present; this is a potentially relevant execution surface, but the signal provides no evidence that it is unsafe.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest gap in repository security hygiene.
The repository has no security policy, which reduces transparency about vulnerability reporting and response expectations.
Both workflows were analyzed successfully, with no untrusted checkouts or script injection; however, all 10 action references are unpinned, one workflow has top-level write access, and high-confidence adhoc-package findings weaken build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.72|^3.0 | — | — |
laravel/framework Version ^10.10|^11.0|^12.0|^13.0 | — | — |
coduo/php-to-string Version ^3.2 | — | — |
spatie/laravel-query-builder Version ^5.7|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.