The package includes tests, a clear README, an explicit MIT license, and a matching source repository. Recent registry releases are reassuring, but the repository shows no commits in three months and its auto-tag workflow combines a workflow-run trigger with an untrusted checkout and high-confidence template injection.
48%
Total Score
50
100
50
The auto-tag workflow has a workflow-run trigger and an untrusted checkout in the same workflow, alongside a high-confidence template-injection finding; this creates a serious release-workflow supply-chain concern. All nine analyzed action references are also unpinned, and the audit found an additional high-confidence adhoc-package installation.
The repository recorded zero commits and zero active maintainers in the last three months, weakening confidence that fixes and maintenance are currently moving forward.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/filesystem Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.