MIT licensing, tests, release notes, and organizational backing provide useful transparency. The workflow audit found no dangerous triggers or findings, but its action references still need pinning.
70%
Total Score
75
50
93
67
Eleven runtime dependencies create a relatively broad dependency surface for a Laravel feature package, but the listed dependencies are coherent with its webinar, authentication, storage, and integration features.
No commits and no active maintainers were recorded in the last three months. Recent registry releases partly offset this, but the lack of observed source activity raises maintenance risk.
The repository has no security policy file, leaving vulnerability reporting and response expectations less transparent.
Version 0.1.44 is not a stable-major release, so compatibility expectations are lower, but it is not marked as a prerelease and recent versions show no prerelease churn.
All four workflows were analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all 10 action references are unpinned, and the workflows lack top-level permissions blocks, creating a meaningful reproducibility and workflow-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
escolalms/auth Version ^0 | — | — |
escolalms/cart Version ^0 | — | — |
escolalms/core Version ^1 | — | — |
escolalms/tags Version ^0 | — | — |
escolalms/files Version ^0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.