Healthy and suitable to use, with routine review of its install scripts and CI permissions. It has frequent releases, an active organization-owned repository, tests, release notes, and security tooling; the main caveats are lifecycle scripts and one workflow with write access.
86%
Total Score
100
50
100
75
The package has 10 runtime dependencies, including framework and Filament components, which is a meaningful integration surface but consistent with a Laravel starter kit.
Four install or update lifecycle scripts can execute package-controlled commands during Composer operations, creating additional supply-chain exposure. This is a genuine caution even though the package appears actively maintained.
Three workflows omit top-level permissions and one auto-release workflow grants top-level write access, which increases CI credential exposure. The absence of detected dangerous workflow patterns limits the severity to caution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0 | — | — |
livewire/blaze Version ^1.0 | — | — |
filament/filament Version ^4.5 | — | — |
laravel/framework Version ^13.0 | — | — |
livewire/livewire Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.