It has clear documentation, tests, an MIT license, security policy, and organization backing. Maintenance has stopped recently, and the automated workflows contain several high-confidence hygiene issues that warrant caution.
42%
Total Score
75
100
80
100
The package borrows the identity of the much more established laravel/sail package, with an explicit lookalike identity signal; consumers could install the wrong package.
The audit completed all five workflows and found high-confidence template-injection issues, an unpinned container image, and spoofable bot conditions; all 11 action references are unpinned. The pull_request_target workflow had no untrusted checkout or script-injection sink, which limits the severity of that trigger itself.
The package has only three releases and no releases in the last 12 months, with a median interval of about two years, indicating a sparse cadence.
There were no commits and no active maintainers in the last three months, a concrete sign that maintenance has stalled.
There are no new or closed issues or pull requests in the last month, although two pull requests remain open, suggesting limited current project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.