This is my package laravel-auth-cache
67%
Total Score
caution
Usable with caveats: a high-confidence workflow audit flags unsafe conditions in Dependabot's auto-merge workflow.
The package runs a post-autoload-dump script during installation. This is an additional execution surface, but the signal provides no indication that the script is unsafe.
All nine recent commits came from one contributor, so maintenance depends entirely on a single active developer.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
The audit analyzed all four workflows and found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow; seven of nine action references are also unpinned. No untrusted checkout or script-injection sink was found, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.