Clear licensing, tests, and release notes improve confidence. The workflow is auditable but uses three unpinned actions, and no security policy is published.
68%
Total Score
50
93
50
The package has existed for nearly 12 years with 71 releases, but only one release in the last 12 months indicates a slower current cadence.
All recent commit activity comes from one contributor, leaving maintenance dependent on a single active person.
Only one commit was recorded in the last three months, with one active maintainer, showing very limited recent development activity.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities.
The only workflow was fully analyzed with no detected high-confidence findings or unsafe untrusted triggers, but all three action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version ^12 || ^13 | — | — |
illuminate/validation Version ^12 || ^13 | — | — |
rdx/laravelcollective-html Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.