The package includes a README, changelog, repository tests, a clear MIT license, and no install-time scripts. Its workflows use Dependabot but contain a high-confidence bot-condition warning and leave all nine actions unpinned.
55%
Total Score
50
90
75
Only three releases were published, all between November 5 and November 24, 2022, with no releases in the last 12 months. This makes the dependency appear stale despite the repository being available.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push timestamp does not show sustained current development.
No security policy was found in the linked repository, leaving vulnerability reporting and response expectations undocumented.
All nine analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull-request trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^7.0|^8.0|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.