Healthy and suitable to depend on. It has a long, steady release history, active multi-contributor maintenance, clear Laravel organizational backing, and strong repository hygiene; the only caveats are install-time scripting and some writable CI workflows.
94%
Total Score
100
100
100
70
One of six workflows uses pull_request_target, which can require careful review, but there are no untrusted checkouts or script-injection findings to amplify the risk.
A post-autoload-dump install script executes during dependency installation, which adds execution-supply-chain exposure, although this is a common Composer mechanism and no separate evidence indicates misuse.
All workflows declare token permissions, and half use read-only permissions; three workflows request top-level write access, which is broader than ideal but is moderated by explicit permission declarations and organization backing.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10364 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. laravel/fortify is vulnerable to Session Fixation in versions 1.0.0 - 1.25.4. | 1.0.0 - 1.25.4 | Medium |
CVE-2022-25838 laravel/fortify is vulnerable to Authentication Bypass by Capture-replay in versions 0.0.0 - 1.11.1. | 0.0.0 - 1.11.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
laravel/passkeys Version ^0.2.0 | — | — |
illuminate/console Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
pragmarx/google2fa Version ^9.0 | — | — |
bacon/bacon-qr-code Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.