laravel/pint v1.32.1 appears to be a healthy, actively maintained dependency. It has a long release history with 95 releases, 21 releases in the last 12 months, and a median release interval of about 9 days; the current release is stable and not deprecated. The linked Laravel organization repository is active, well-backed, tested, licensed, security-aware, and directly matches the package. The main reservations are that recent commits are concentrated in one contributor and several workflows have top-level write permissions, but these concerns are moderated by nine active contributors, organization ownership, and otherwise strong repository and release hygiene.
88%
Total Score
90
100
100
80
One of six workflows uses pull_request_target, which warrants review because that trigger can increase CI supply-chain exposure, but there are no untrusted checkouts or script-injection findings.
The leading contributor made 50 of 60 recent commits, creating concentration risk. However, eight additional contributors were active and the repository is organization-owned, which provides some maintenance handoff capacity.
All analyzed workflows declare permissions, but four grant top-level write access; explicit permissions improve transparency, while broad write capability remains a workflow-hardening concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.