The starter kit has current releases, substantial tests, and recent repository activity. Its small contributor base, missing security policy, and unpinned workflow actions leave some maintenance and build-integrity risk.
78%
Total Score
75
94
50
The package declares several Composer lifecycle scripts, including post-create and post-update hooks. These are relevant install-time behavior that consumers should inspect, though their presence alone is not evidence of unsafe behavior.
Two contributors are active, but one accounts for 13 of 14 recent commits, leaving maintenance highly concentrated for a user-owned project.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no published security policy, making vulnerability reporting and response expectations less clear.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned. That weakens build reproducibility without indicating a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0 | — | — |
laravel/sanctum Version ^4.0 | — | — |
filament/filament Version ^5.0 | — | — |
laravel/framework Version ^13.0 | — | — |
livewire/livewire Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.