A clear README, repository tests, MIT licensing, and organization backing support adoption. Recent release activity is strong, but no commits or active maintainers were recorded in the last three months, and the publishing workflow has unpinned actions plus trusted-publishing and cache findings.
62%
Total Score
75
100
89
50
No commits and no active maintainers were recorded in the last three months. This is a meaningful maintenance concern, although the recent release history shows the project was active earlier.
The repository has zero stars, forks, and watchers, so there is little external adoption evidence; popularity is supporting evidence rather than a verdict.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and prevention gap.
The repository has no security policy, making vulnerability reporting expectations unclear for dependents.
The single analyzed workflow has two unpinned action references, which is a hygiene concern, and the audit reports high-severity cache-poisoning with low confidence plus high-confidence trusted-publishing usage. No untrusted checkout or script-injection sink was found, limiting the risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0 | — | — |
inertiajs/inertia-laravel Version ^2.0 | — | — |
spatie/laravel-query-builder Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.