Its MIT license, stable release line, substantial scaffold, and matching repository provide useful transparency. The workflow audit found no high-risk findings, but all seven actions are unpinned and the repository has had no commits in three months. Pin a maintained commit or fork before relying on it.
58%
Total Score
50
75
50
Four releases were published in the last 12 months, but they were clustered around the initial release period rather than showing an ongoing cadence. This supports a cautionary maintenance assessment without proving abandonment on its own.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have stalled after the initial release period.
The repository has only 4 stars, 1 fork, and no watchers, indicating a very small external user base. Low popularity is supporting evidence rather than a health verdict, but it provides little independent confidence in continued maintenance.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear. This is a transparency gap, not evidence of a security flaw.
The single workflow was fully analyzed with no untrusted checkout, injection, or audit findings, but all 7 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^2.10.1 | — | — |
laravel/fortify Version ^1.31.1 | — | — |
laravel/framework Version ^12.34 | — | — |
laravel/wayfinder Version ^0.1.12 | — | — |
nunomaduro/essentials Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.