Usable with caveats: the package has strong Laravel organization backing, clear licensing, tests, release notes, and a matching source repository. However, registry history shows no release in over a year and no commits in the last three months, while the assessed v11.2.0 conflicts with the registry's recorded latest v10.0.4.
66%
Total Score
88
50
89
80
One workflow uses pull_request_target, which warrants care because it can run with elevated repository context, but there are no untrusted-checkout or script-injection findings among the four analyzed workflows.
The framework declares 37 runtime dependencies, reflecting a substantial integration surface; this is expected for a full web framework but increases maintenance coupling compared with a small library.
The package has a long history and 136 releases, but the registry records no releases in the last 12 months and places the latest release on November 26, 2024, which raises maintenance and release-publication concerns.
There were zero commits and zero active maintainers in the last three months, a meaningful sign of slowed development; the recent repository push and one merged pull request provide only limited compensation.
All workflows declare top-level permissions, but three grant write access rather than read-only access, increasing the impact of workflow mistakes even though permissions are explicit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^7.0 | — | — |
illuminate/bus Version ^11.0 | — | — |
illuminate/log Version ^11.0 | — | — |
illuminate/auth Version ^11.0 | — | — |
illuminate/http Version ^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.