The package has clear documentation, tests, release notes, a matching repository, and a security policy. Its framework-heavy dependency set and single-person publishing base leave less room for continuity than a mature project.
67%
Total Score
75
50
83
75
Ten runtime dependencies, including Laravel Nova, Passport, and MCP components, create a meaningful compatibility surface. This is expected for a Nova integration but makes upgrades more involved.
Only one registry account has publishing access, leaving a thin publishing base and higher bus-factor risk. The linked repository and active release evidence provide some compensation.
The package is brand new, with two releases in about 47 minutes and no longer-term release record. That supports active initial work but provides little evidence of sustained maintenance.
Version v0.2.0 is not a stable major release, so compatibility and maintenance patterns are not yet established. It is not marked as a prerelease, which partly offsets the concern.
The sole workflow was fully analyzed, uses all four actions with pinned references, read-only permissions, and no untrusted checkout or script-injection findings. A high-confidence bot-conditions warning in ci.yml is a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^1.0.1 | — | — |
laravel/nova Version ^5.11 | — | — |
illuminate/auth Version ^12.41.1 || ^13.0 | — | — |
laravel/passport Version ^13.8 | — | — |
illuminate/console Version ^12.41.1 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.