Package Health

lomkit/laravel-rest-api

Organization backing, four active contributors, and a clear README, tests, and release notes add useful support. GitHub Actions uses five unpinned references and the repository has no security policy, so workflow and disclosure hygiene are weaker than the maintenance picture.

Latest v2.23.2PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The project uses Composer, but no security scanning tools were detected. The build setup is present, while automated security coverage is not evident.

Security policycaution

The repository has no security policy. That weakens vulnerability-reporting transparency, although recent releases and active commits provide compensating maintenance evidence.

Workflow auditcaution

Both workflows were analyzed successfully with no dangerous sinks or audit findings, and one scopes permissions at job level. However, all five action references are unpinned, which leaves workflow dependencies less reproducible.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-977435
lomkit/laravel-rest-api is vulnerable to Incorrect Authorization in versions 2.0.0 - 2.23.1.
2.0.0 - 2.23.1
Medium
CVE-2025-48490
lomkit/laravel-rest-api is vulnerable to Improper Input Validation in versions 0.0.0 - 2.13.0.
0.0.0 - 2.13.0
Medium

Package versions

Maintainers

Gautier Deleglise

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version ^12|^13
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform