Usable with caveats. The package is mature, licensed, documented, tested, and recently released, but there were no commits or active maintainers in the last three months and the repository lacks a security policy.
72%
Total Score
67
100
94
75
The repository recorded zero commits and zero active maintainers in the last three months, despite the recent release; this creates a meaningful risk that maintenance has slowed or paused.
There are no open issues or pull requests, but there was also no issue or pull-request activity in the last month, so this is limited evidence of ongoing support.
Composer is used for the build, but no security scanning tools were detected; this is a transparency and assurance gap, though not evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
The sole workflow has no top-level token permissions declaration. No write permissions were detected, but explicitly declaring least-privilege permissions would improve workflow hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10232 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. gr8shivam/laravel-sms-api is vulnerable to Improper Input Validation in versions 1.0.0 - 3.0.6. | 1.0.0 - 3.0.6 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.