Serve Laravel Assets from a Content Delivery Network (CDN)
68%
Total Score
caution
No commits in three months, only three releases, and every workflow action is unpinned despite a current release.
The package has only 3 releases over about 3 years, with one release in the last 12 months and a median interval of about 579 days. The release made today shows activity, but the overall cadence remains sparse.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although it was pushed alongside the current release, there is little recent development activity to demonstrate ongoing maintenance.
Composer is used as the build tool, which fits the package, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. This weakens the project's disclosure and response transparency, though it is not evidence that the package is unsafe.
The single workflow was fully analyzed with no audit findings and no untrusted checkout or script-injection paths, but all 4 action references are unpinned. That leaves build inputs less reproducible and less resistant to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.