The project has a large dependency surface and no published security policy. Its source is tested, actively changing, licensed, and has release notes, but the workflow audit found a high-confidence template-injection issue that deserves review.
68%
Total Score
100
50
94
63
The release declares 49 runtime dependencies, including many framework and application integrations, which increases maintenance and transitive-dependency complexity.
Four install or update lifecycle scripts can execute package-controlled commands during Composer operations, adding operational review burden. This is expected to some extent for a Laravel application but remains a supply-chain consideration.
This is the package's first and only release, published less than one day ago, so there is no release history to establish long-term stability. Active repository commits partly compensate for the limited registry history.
The repository has no security policy, leaving disclosure and response expectations undocumented.
All five workflows were analyzed and all 15 action references are pinned, with no untrusted checkout or script-injection trigger found. However, the high-confidence template-injection finding in update-changelog.yml and one workflow with top-level write permissions are meaningful workflow hygiene risks.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^0.9.5 | — | — |
geoip2/geoip2 Version ^3.4 | — | — |
laravel/tinker Version ^3.0 | — | — |
livewire/blaze Version ^1.0 | — | — |
laravel/horizon Version ^5.50 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.