The repository is licensed, tested, and clearly matched to the package, while workflows completed without audit findings. One maintainer, no prior release history, and three unpinned workflow actions leave support and build reproducibility uncertain.
67%
Total Score
67
100
88
67
Only one registry publishing maintainer is listed. That is workable for a small package but leaves limited visible publishing redundancy.
This is the first release, published today, so there is no track record for maintenance or release consistency yet. Its immediate publication is not itself a severe concern.
There were no commits or active maintainers in the last three months, but the repository was only created or updated today, so this is mainly an absence of history rather than evidence of collapse.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported. For a new, small package this is a moderate documentation gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.