The repository has two active contributors, tests, a changelog, and Dependabot. Install scripts and broad workflow write permissions deserve extra review before adoption.
72%
Total Score
83
100
94
50
The package runs four Composer lifecycle scripts, including post-create and post-update hooks; these are common for Laravel applications but add install-time execution that should be reviewed.
The package is only 119 days old and has just two releases, both within the first few days, so its maintenance track record remains limited.
Two commits from two active maintainers in the last three months show some current maintenance, though the volume is still low for a project with a short history.
No security policy was found in the repository, reducing transparency about how vulnerabilities should be reported.
All five workflows were analyzed, all six action references are pinned, and no audit findings or untrusted checkout sinks were reported. However, three workflows grant top-level write permissions, which is broader than necessary.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0 | — | — |
laravel/framework Version ^13.8 | — | — |
livewire/livewire Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.