The package is clearly documented, licensed, tested in its repository, and backed by an organization. Recent development is limited to one contributor and one commit in three months, while workflow checks found a high-confidence bot-condition issue and all 12 action references are unpinned.
68%
Total Score
63
100
94
50
A post-autoload-dump lifecycle script runs during installation. This is worth noting as install-time behavior, but the signal provides no evidence that it is unsafe or unusually broad.
Only one registry account has publish access, which is a modest publishing bus factor. The repository is organization-owned, partially compensating for the narrow registry maintainer list.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown in this signal.
Only one commit from one active maintainer was recorded in the last three months, indicating thin recent maintenance capacity.
No security policy was found in the repository. This reduces transparency for reporting and handling vulnerabilities, although it does not by itself show abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
honed/core Version ^0.55.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
inertiajs/inertia-laravel Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.