The README, tests, MIT license, and steady release history make the package easy to evaluate. Recent source activity is limited to one commit from one maintainer, and all seven workflow actions are unpinned.
68%
Total Score
50
94
75
One contributor made all recent commits, leaving maintenance capacity concentrated in a single person without evidence of a broader active base.
Only one commit was recorded in the last three months, indicating limited recent maintenance despite the strong registry release cadence.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability-reporting expectations less clear for a package intended to seed applications.
The sole workflow was fully analyzed with no audited findings or untrusted triggers, but all seven action references are unpinned, reducing build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^13.7 | — | — |
nunomaduro/essentials Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.