The package is clearly identified, licensed, documented, and has no install-time scripts. Its small user base, absent security policy, and unpinned workflow image add modest maintenance and hygiene concerns.
42%
Total Score
0
75
67
The package has only 2 releases, and its latest release was over 5 years ago; this is strong evidence of abandonment risk for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history and indicating no current maintenance.
The repository has 2 stars, 1 fork, and 1 watcher, showing a very small adoption and review base. This is supporting caution rather than a verdict on its own.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. The gap matters, but is secondary to the prolonged inactivity.
Both workflows were analyzed successfully, but all 5 action references are unpinned and the audit found a high-confidence unpinned container image. This is a supply-chain hygiene weakness, though not severe enough to make the package unfit by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-dashboard Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.