The beta channel and workflow setup add some uncertainty. Tests, release notes, security scanning, and active organizational maintenance provide substantial reassurance.
80%
Total Score
100
94
50
Several Composer install and update lifecycle scripts are present, which is expected for a Laravel application with setup commands but increases install-time behavior that consumers should understand.
No repository security policy was found, leaving vulnerability-reporting expectations and handling procedures less transparent.
This is a beta release, and all recent releases are prereleases, so compatibility may still change. The stable major version label provides some maturity context but does not remove the prerelease risk.
All nine workflows use top-level write permissions and all 30 analyzed action references are unpinned, while a high-confidence template-injection finding appears in docker-tag.yml. No untrusted checkout or script-injection path was found, so this is a workflow hygiene concern rather than a standalone severe health risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^4.6 | — | — |
lcobucci/jwt Version ^5.6 | — | — |
predis/predis Version ^3.2 | — | — |
dedoc/scramble Version ^0.13.26 | — | — |
laravel/reverb Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.