Service-based cookie consent for Laravel with versioned preferences and browser script gating.
78%
Total Score
healthy
A well-documented new package with strong project structure, but little track record and fully unpinned workflow actions.
The package runs a post-autoload-dump lifecycle script during installation. This is a supply-chain and install-behavior consideration, but the signal alone does not establish unsafe behavior.
The package is only 1 day old, despite 12 releases in that period and a median release interval of 0 days. This shows active initial development but provides little evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a minor transparency gap for a package handling consent and audit data.
Both workflows use read-only permissions and the audit found no sinks, high-severity findings, or incomplete files. However, all 5 action references are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 || ^13.0 | — | — |
illuminate/view Version ^12.0 || ^13.0 | — | — |
illuminate/cookie Version ^12.0 || ^13.0 | — | — |
illuminate/console Version ^12.0 || ^13.0 | — | — |
illuminate/routing Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.