Tests, release notes, security policy, and Dependabot provide useful maintenance evidence. Install-time scripts and a high-confidence workflow condition warning warrant checking the automation before adoption.
82%
Total Score
88
100
100
67
Four install and update lifecycle scripts run during Composer operations, increasing execution surface for consumers, although these scripts are consistent with a Laravel starter project.
The package and repository are owned by the same individual account, so the project has direct ownership but no organization-level maintenance backing is shown.
All six workflows were analyzed, all 15 action references are pinned, and no untrusted checkout or script-injection paths were found. However, a high-confidence bot-conditions finding reports that actor context may be spoofable in the Dependabot auto-merge workflow, while three workflows grant top-level write permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0.0 | — | — |
filament/filament Version ^5.0 | — | — |
laravel/framework Version ^13.0 | — | — |
livewire/livewire Version ^4.0 | — | — |
nativephp/desktop Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.