The package is clearly documented, licensed, and backed by an active organization with security tooling. Its workflows need tighter pinning and narrower token permissions, but current maintenance activity and clean audit findings reduce the concern.
84%
Total Score
100
100
100
75
All 12 workflows were analyzed with no audit findings, no untrusted checkout or script-injection sinks, and no high-severity issues. However, all 17 action references are unpinned and 10 workflows grant top-level write permissions, creating moderate workflow hygiene and token-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-lang/publisher Version ^16.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.