The package includes tests, a changelog, and a matching MIT license, while dependency and security tooling are present. Its source has had no commits in over two years, and the workflow audit found a high-confidence bot-condition issue alongside broad permissions and unpinned actions.
42%
Total Score
25
50
88
33
The package has had 3 releases since December 2023 and none in the last 12 months; the latest release is nearly three years old, indicating likely abandonment.
The repository recorded zero commits and zero active maintainers in the last three months; combined with no registry releases in the last year, this is strong evidence of stalled maintenance.
All 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-condition finding affects the Dependabot auto-merge workflow. No untrusted checkout or script injection was found, but the combined workflow hygiene is a real supply-chain concern.
Nine runtime dependencies, including Laravel, Livewire, Passport, and repository packages, create a relatively broad dependency surface for a package with limited recent release activity.
The package runs a post-autoload-dump script during installation. This is a meaningful execution surface, but the signal provides no evidence that the script is unsafe or unusually broad.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^4.2 | — | — |
laravel/passport Version ^11.3 | — | — |
livewire/livewire Version ^2.10 | — | — |
illuminate/contracts Version ^10.0 | — | — |
prettus/l5-repository Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.