The package has a clear README, an explicit license, and release notes for this version. Recent work is concentrated in one contributor, while the workflow uses broad permissions and unpinned actions; organization backing provides some continuity.
72%
Total Score
67
100
50
One contributor made all six commits in the last three months, creating a thin maintenance base; organization ownership partly reduces handoff risk but does not remove the concentration.
Six commits in the last three months show recent activity, though all activity is concentrated in one active maintainer.
The repository has no security policy. This is a transparency and maintenance gap, although the package is small and the workflow audit found no concrete high- or medium-severity issue.
The only workflow was fully analyzed with no reported audit findings or untrusted sinks, but all three action references are unpinned and the workflow grants top-level write permissions, leaving avoidable supply-chain and token-scope hygiene gaps.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/boost Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.