It includes tests, recent release notes, and a working repository, but only one contributor has committed in the last three months. Unpinned workflow actions and no security policy reduce transparency further.
40%
Total Score
50
75
50
Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a major adoption and maintenance risk even though the release itself is recent.
All recent commits came from one contributor, giving a 100% top-contributor share. There is no observed second active contributor to provide maintenance resilience.
The repository recorded only 1 commit in the last 3 months. Recent release activity exists, but the observed ongoing development pace is thin.
The repository has no security policy. For a small package this is not a severe risk by itself, but it weakens the project's disclosure and response transparency.
The single workflow was fully analyzed and uses read-only permissions with no dangerous findings, but both of its 2 action references are unpinned. That leaves avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^5.1||^6.0||^7.0||^8.0||^9.0||^10.0||^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.