The repository is intact, licensed, documented, and has tests plus a release note. Workflow actions are all unpinned and no security policy is provided, adding maintenance and supply-chain hygiene concerns.
68%
Total Score
50
100
92
50
The package has 10 releases over more than six years, but it has had no release in the past year, which points to slowing maintenance.
The repository had zero commits and zero active maintainers in the past three months. The recent release provides some compensating evidence, but current maintenance capacity is unclear.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it does not by itself indicate abandonment.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 5 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.