Its documentation, tests, release notes, and security policy are strong. Recent work still depends on one contributor, despite organization backing.
45%
Total Score
83
100
83
100
The package is flagged as borrowing the identity of laravel/octane, a much more established package, even though artifact overlap is zero. That makes it unclear whether consumers intended to install this package and is a severe adoption risk.
The package is 105 days old with three releases and a median interval of about 21 days, showing active early development but limited maturity.
All six recent commits came from one contributor. Organization backing helps provide continuity, but no second active contributor is shown, leaving maintenance capacity concentrated.
All eight workflows were analyzed successfully, all 12 action references are pinned, and no untrusted checkout or script-injection sink was found. Four workflows grant top-level write permissions, which is a mild hygiene caution, but no untrusted path reaches those permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.0 | — | — |
laravel-chronicle/core Version ^1.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.