Healthy and suitable to depend on, backed by a mature Laravel project with regular releases, clear licensing, tests, and active repository maintenance. Recent activity is concentrated in one contributor, and several workflows have write access, so review updates normally.
84%
Total Score
88
100
100
67
One of six workflows uses pull_request_target, which warrants attention, but no workflow performs an untrusted checkout or detected script injection.
Only one commit was recorded in the last three months, which is thin recent activity, but it is consistent with a mature package that also had six releases in the last year and recent repository updates.
All workflows declare permissions, and three use read-only permissions; three also have top-level write access, which increases workflow-impact risk but is not inherently a maintenance failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psy/psysh Version ^0.12.0 | — | — |
illuminate/console Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
symfony/var-dumper Version ^5.4|^6.0|^7.0|^8.0 | — | — |
illuminate/contracts Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.