The package includes tests, release notes, security tooling, and an active source project. Its workflows use 29 unpinned actions and contain high-confidence template-injection findings. Pin v1.0.3 explicitly because the registry may otherwise resolve v13.0.0.
72%
Total Score
100
50
94
75
The release declares 22 runtime dependencies spanning Laravel, Filament, payment, realtime, and other integrations, creating a broad maintenance and update surface for adopters.
Four install and update lifecycle scripts run during Composer operations, increasing installation complexity and the code executed by consumers. This is common for a Laravel application but remains a supply-chain hygiene consideration.
The package is only 64 days old and all four releases arrived within roughly 37 minutes, so there is limited evidence of sustained release maturity despite recent activity.
All six workflows were analyzed successfully, but all 29 action references are unpinned, and high-confidence template-injection findings appear in composer-require.yml and lint.yml. No untrusted checkout or script-injection trigger was found, so this is workflow hygiene risk rather than a severe standalone finding.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/octane Version ^2.3 | — | — |
laravel/reverb Version ^1.10 | — | — |
laravel/tinker Version ^3.0 | — | — |
laravel/cashier Version ^16.6 | — | — |
laravel/horizon Version ^5.47 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.