Laravel integration of Cooper: the configuration repository filled from a CASC document, .env files read by Cooper, and cooper:import to move config/*.php into CASC.
68%
Total Score
caution
A first release with no observed commit history and all workflow actions unpinned keeps this package in the caution range.
This package is brand new: it is 0 days old and has only one release, so there is no demonstrated release track record yet.
The repository reports 0 commits and 0 active maintainers during the last 3 months. Because the package was released only 0 days ago, this may reflect its newness, but it leaves maintenance capacity unproven.
No security policy is present in the repository. This is a transparency gap for reporting vulnerabilities, though it is not evidence of an unsafe implementation by itself.
Version v0.1.0 is not a stable major release, which signals an early API and maintenance stage, although it is not marked as a prerelease.
All 8 analyzed action references are unpinned, which weakens build reproducibility. One workflow grants top-level write permission, but the audit found no untrusted checkouts, script injection, or high- or medium-severity findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
joetjen/cooper Version ^0.1 | — | — |
symfony/console Version ^7.0 || ^8.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
illuminate/config Version ^11.0 || ^12.0 || ^13.0 | — | — |
laravel/framework Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.