Healthy and suitable to depend on. It has frequent stable releases, an active non-archived repository with four recent contributors, tests, release notes, and clear Laravel organization backing. Review its Composer post-install behavior and broad workflow write permissions as routine supply-chain precautions.
91%
Total Score
100
50
100
70
One of nine workflows uses pull_request_target, creating some CI security exposure, but there are no untrusted checkouts or script-injection findings.
The package declares 21 runtime dependencies, including several Laravel components and Livewire; this is a relatively broad integration surface but is coherent with a performance-monitoring dashboard package.
A post-autoload-dump install-time script is present, which adds execution surface during installation; this is a routine Composer hook but merits review before adoption.
Six of nine workflows declare top-level write permissions, broader than necessary in many repositories; three use read-only permissions, so this is a meaningful but not disqualifying workflow-hardening concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10350 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. laravel/pulse is vulnerable to Deserialization of Untrusted Data in versions 1.0.0 - 1.6.0. | 1.0.0 - 1.6.0 | High |
CVE-2024-55661 laravel/pulse is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.3.1. | 0.0.0 - 1.3.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
league/uri Version ^7.5.1 | — | — |
nesbot/carbon Version ^2.67|^3.0 | — | — |
illuminate/auth Version ^10.48.4|^11.0.8|^12.0|^13.0 | — | — |
illuminate/http Version ^10.48.4|^11.0.8|^12.0|^13.0 | — | — |
illuminate/view Version ^10.48.4|^11.0.8|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.