The package includes repository tests, a changelog, a security policy, and a clear MIT license. Its workflows use six unpinned actions, while no commits were recorded in the last three months despite continued registry releases.
65%
Total Score
75
100
93
75
The package runs a post-autoload-dump install-time script. A lifecycle script adds execution during installation, so it is a supply-chain hygiene concern, although this signal does not show that the script is unsafe.
The repository recorded 0 commits and 0 active maintainers in the last three months. That is a meaningful maintenance concern, though 8 registry releases in the last 12 months provide partial compensating evidence.
No new issues or pull requests were recorded in the last month, and there were no merged pull requests. This is a weak maintenance signal, but it is less concerning alongside the continuing release history.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment, especially with a repository security policy present.
All 5 workflows were analyzed without audit findings or untrusted-checkout and script-injection sinks. However, all 6 analyzed action uses are unpinned and 2 workflows grant top-level write permissions, creating moderate workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.66.0|^3.0 | — | — |
laravel/prompts Version ^0.1.24|^0.2.0|^0.3.0 | — | — |
symfony/console Version ^6.0|^7.0 | — | — |
laravel/framework Version ^10.10.1|^11.0|^12.0 | — | — |
laminas/laminas-diactoros Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.