It has a long release history, recent commits from three contributors, tests, and a security policy. The package name and identity overlap signal creates a serious risk that consumers may choose the wrong package.
42%
Total Score
100
100
88
100
The signal reports that laravel-zero/laravel-zero borrows the identity of laravel/reverb, which has far more downloads. This is strong evidence that consumers may select the wrong package, despite the reported zero artifact overlap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-zero/framework Version ^13.0 | — | — |
laravel-zero/foundation Version ^13.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.