There is no security policy or security scanning, and installation runs four lifecycle scripts. A repository-backed README and tests help, but the small project shows limited ongoing activity.
57%
Total Score
75
83
67
Four install and update lifecycle scripts run during Composer operations, increasing installation complexity and the amount of package code executed automatically. This is a meaningful supply-chain hygiene concern for a project template.
The package has six releases over about 16 months, but none in the last 12 months, indicating that maintenance may have stopped. Its earlier roughly 18-day median release interval provides some evidence of prior activity.
There were no commits and no active maintainers in the last three months, which is strong evidence of currently limited maintenance activity.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this modestly reduces confidence in project maturity rather than determining the verdict.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a transparency and maintenance gap, not proof of an unsafe release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^2.8 | — | — |
laravel/sanctum Version ^3.3 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
laravel/framework Version ^10.10 | — | — |
stripe/stripe-php Version ^14.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.