Package Health

laravel/fortify

Healthy and suitable to depend on. It has a long, steady release history, active multi-contributor maintenance, clear Laravel organizational backing, and strong repository hygiene; the only caveats are install-time scripting and some writable CI workflows.

Latest v1.39.0PackagistPackagist

94%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Are you affected? Scan for Free

Health Score Breakdown

Dangerous workflowscaution

One of six workflows uses pull_request_target, which can require careful review, but there are no untrusted checkouts or script-injection findings to amplify the risk.

Lifecycle scriptscaution

A post-autoload-dump install script executes during dependency installation, which adds execution-supply-chain exposure, although this is a common Composer mechanism and no separate evidence indicates misuse.

Token permissionscaution

All workflows declare token permissions, and half use read-only permissions; three workflows request top-level write access, which is broader than ideal but is moderated by explicit permission declarations and organization backing.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2025-10364 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
laravel/fortify is vulnerable to Session Fixation in versions 1.0.0 - 1.25.4.
1.0.0 - 1.25.4
Medium
CVE-2022-25838
laravel/fortify is vulnerable to Authentication Bypass by Capture-replay in versions 0.0.0 - 1.11.1.
0.0.0 - 1.11.1
High

Package versions

Maintainers

Taylor Otwell

Direct Dependencies

DependencyLast ReleaseScore
laravel/passkeys
Version ^0.2.0
illuminate/console
Version ^11.0|^12.0|^13.0
illuminate/support
Version ^11.0|^12.0|^13.0
pragmarx/google2fa
Version ^9.0
bacon/bacon-qr-code
Version ^3.0

Weekly Downloads

Info

Last Published
28 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform