The project has a strong release record and an active organization-owned repository with tests, documentation, and a security policy. Recent development has stopped, and all eight workflow action references are unpinned, leaving meaningful maintenance and build-integrity concerns.
66%
Total Score
63
100
89
75
The repository recorded zero commits and zero active maintainers over the last three months. That is a concrete recent maintenance gap despite the strong release history.
The package runs post-autoload-dump, post-install-cmd, and post-update-cmd scripts. Composer lifecycle hooks can be normal for a Laravel package, but they add install-time behavior that warrants attention.
There were no new issues or pull requests and no merged pull requests in the last month, while 48 issues and 64 pull requests remain open. This indicates a recent slowdown in project response.
The repository uses Composer and Task, but no security-scanning tools were detected. This is a modest transparency and hygiene gap, partly offset by the separate security policy.
Version v0.100.1 is not a prerelease and has no recent prerelease share, but the project remains below a stable major version, so compatibility guarantees may be less mature.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.