The package has clear MIT licensing, a focused dependency set, release notes, and a repository that matches its name. Its last release was about three years ago, with no recent commits, while the build workflow leaves both referenced actions unpinned.
54%
Total Score
50
100
88
67
Only two releases exist, both from August 2023, and there have been no releases in roughly three years. This is substantial evidence of limited ongoing maintenance for a Laravel integration package.
There were no commits and no active maintainers in the last three months. Combined with the roughly three-year release gap, this indicates a largely inactive project rather than merely a quiet release cadence.
Composer is used for the build, which fits the package ecosystem, but no security scanning tooling is present. This is a modest transparency and maintenance gap, not a severe risk on its own.
The repository has no security policy. For a package handling administrator and user-management functionality, this weakens the project's documented process for reporting and addressing security issues.
The single workflow was fully analyzed with no dangerous triggers or audit findings, and it scopes permissions at job level. However, both of its action references are unpinned, leaving the build exposed to changes in referenced action versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.