CSS-agnostic form rendering via Laravel Blade
70%
Total Score
100
100
86
50
One workflow uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can expose elevated workflow privileges, although no untrusted checkout or script injection was detected.
The project has existed for over 11 years with six releases, but it has made no registry release in about 16 months. That slows confidence in compatibility, despite the long project history.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities, though this is a hygiene gap rather than evidence of abandonment.
Three of four workflows declare top-level write permissions and one lacks top-level permissions entirely, leaving workflow privileges broader or less explicit than ideal.
Version v0.3.0 is not a prerelease, but it remains below a stable major version, so its API and compatibility guarantees may be limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.