Clear licensing, documented release notes, and a security policy support straightforward adoption. The only notable concern is an unpinned container image in CI; active organizational maintenance and broad recent participation keep it limited.
86%
Total Score
100
100
100
67
The package runs a post-autoload-dump script during installation. This is a meaningful install-time behavior to understand, but the signal alone does not indicate unsafe or excessive lifecycle activity.
All seven workflows were analyzed successfully and all eight action references are pinned, but one high-confidence finding reports an unpinned container image. Four workflows also grant top-level write permissions, adding a smaller CI hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^5.3|^6.0|^7.0|^8.0 | — | — |
laravel/sentinel Version ^1.0 | — | — |
laravel/framework Version ^8.37|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
symfony/var-dumper Version ^5.0|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.