Releases are infrequent, and the repository recorded no commits in the last three months. It has a clear license, tests in the repository, and organization backing.
48%
Total Score
75
100
81
75
The package is flagged as borrowing laravel/pail's identity, with borrows_lookalike_identity true, even though artifact overlap is 0.0 and the README does not identify it as a fork or lookalike.
The package has existed for about 5 years but has only 8 releases, with 1 release in the last 12 months and a median interval of about 261 days.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, limiting evidence of ongoing maintenance despite the recent release history.
The repository has no security policy, which reduces disclosure transparency for a package intended for application integration.
The sole workflow was fully analyzed with no reported audit findings or untrusted code paths, but all 3 action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-json-api/core Version ^5.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.