The release includes a real README, passing tests, and notes documenting 208 tests and 527 assertions. Unpinned workflow actions and the lack of a security policy add modest maintenance and supply-chain hygiene concerns.
67%
Total Score
67
88
50
The package uses post-create-project-cmd and related Composer lifecycle scripts, which are expected for a Laravel starter kit that configures a generated application. They still increase install-time behavior compared with a library.
The repository is owned by an individual user rather than an organization, so there is no provided evidence of organizational handoff capacity to offset the concentrated contributor activity.
The package is only 52 days old but has 10 releases, including 10 in the last 12 months and a median interval of about 18 hours. This shows active iteration, but the short history provides limited evidence of long-term stability.
One maintainer made all 6 commits in the last 3 months, giving the project a single-person bus factor. That creates a real continuity risk for a package intended to seed application code.
Composer build tooling is present, but no security scanning tool was detected. For a starter kit containing authentication and account-management code, this is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twilio/sdk Version ^8.11 | — | — |
livewire/flux Version ^2.15 | — | — |
laravel/tinker Version ^3.0 | — | — |
laravel/framework Version ^13.0 | — | — |
livewire/livewire Version ^4.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.