A dynamic, request-aware CORS policy resolver for Laravel applications
78%
Total Score
63
100
94
88
Only one registry account has publish access. That is consistent with the linked user-owned project, but it leaves limited publishing redundancy.
The repository is owned by an individual rather than an organization, so the single-maintainer and single-publisher concentration is not offset by visible organizational backing.
The package is only 31 days old and has one release, so there is not yet enough history to demonstrate sustained maintenance or compatibility over time.
One contributor made all 16 commits in the last three months, creating a real continuity risk if that maintainer becomes unavailable.
All three workflows were analyzed with no audit findings or untrusted checkouts, but all eight action references are unpinned and two workflows grant top-level write permissions, creating moderate workflow hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
symfony/http-foundation Version ^6.2 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.