PostHog web analytics metrics for Laravel: visitors, sessions, pageviews, bounce rate, session duration, top pages, sources, countries, browsers, devices and realtime users via HogQL queries.
70%
Total Score
caution
A first-day release has no established maintenance record, despite a matching repository and solid publishing hygiene.
The registry namespace and repository owner match, but the owner is an individual rather than an organization, so there is no organizational backing signal to offset the limited maintenance history.
This is the package's first release, published 0 days ago, so there is no release cadence or track record yet. The linked repository and exact-version release notes provide some transparency but cannot establish long-term maintenance.
No commits or active maintainers were observed in the last 3 months. Because the repository is only 0 days old, this is mainly a lack of history rather than evidence that established maintenance has stopped.
All five workflows were analyzed successfully, all 11 action references are pinned, and no untrusted checkout or script injection was found. However, a high-confidence bot-conditions finding reports that actor context may be spoofable in the Dependabot auto-merge workflow, warranting caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-settings Version ^3.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.