Fabriq 3.6.3 appears suitable to depend on from a supply-chain health perspective: it is actively released, currently stable, not deprecated, backed by an organization-owned repository, and supported by recent commits from three contributors. The package and repository include tests, CI workflows, a clear MIT license, and matching source references. The main reservations are the absence of a security policy, undeclared top-level permissions in all analyzed workflows, no automated security-scanning tooling, and a relatively broad runtime dependency set; these are hygiene concerns rather than evidence of abandonment. Registry maintainer access is concentrated in one account, but that is mitigated by the organization backing and broader repository activity.
86%
Total Score
100
50
94
80
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/once Version ^2.0|^3.0 | — | — |
laravel/pint Version ^1.2 | — | — |
doctrine/dbal Version ^3.1|^4.0 | — | — |
aws/aws-sdk-php Version ^3.219 | — | — |
laravel/fortify Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.