The package is licensed, documented, and not deprecated. Its organization-backed repository matches the package, but its small audience limits independent confidence.
62%
Total Score
75
100
89
67
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the frequent release history and recent push provide partial compensation.
The repository has zero stars and two forks, providing little independent evidence of broad use or community review. Popularity is supporting evidence, so this lowers confidence more than it lowers the health assessment.
Composer is used for builds, but no security scanning tools were detected. For a Laravel package, this is a modest transparency and hygiene gap.
The repository has no security policy. This leaves vulnerability reporting and disclosure expectations unclear for consumers of an application-facing package.
The single workflow was fully analyzed with no high-confidence audit findings, but it grants top-level write permissions and uses its one action unpinned. Those are mild supply-chain hygiene weaknesses without an untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.