The package includes tests and its repository clearly matches the package. It was first released only about two hours ago, so maintenance capacity is unproven; install-time scripts and no security tooling add modest review burden.
60%
Total Score
83
67
The package declares four install or update lifecycle scripts: post-autoload-dump, post-create-project-cmd, post-root-package-install, and post-update-cmd. These can be normal for a Laravel starter, but they increase installation review burden.
This package is only about two hours old and has two releases, with the latest published 31 minutes before collection. That is consistent with an initial project, but provides almost no evidence of sustained maintenance.
The repository uses Make and Composer, showing some build structure, but no security scanning tools were detected. That is a modest transparency and maintenance gap, not evidence that the release is unsafe.
No repository security policy was found. For a Laravel starter handling authentication, permissions, and user data, this weakens the project's vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/chisel Version ^0.1.0 | — | — |
laravel/tinker Version ^3.0 | — | — |
laravel/fortify Version ^1.37.2 | — | — |
laravel/framework Version ^13.17 | — | — |
laravel/wayfinder Version ^0.1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.