Tests, a stable release line, and a matching repository add useful confidence. Maintenance depends entirely on one contributor, and the repository has no security policy; keep that ownership risk in mind.
78%
Total Score
67
100
50
The package defines four Composer lifecycle scripts, including project creation and update hooks. These are plausible for a Laravel starter application but add install-time behavior that consumers should understand.
The repository is owned by an individual account rather than an organization. Combined with all recent commits coming from one contributor, there is no provided backing evidence to offset the concentrated maintainer risk.
One contributor made all 83 commits in the last three months, leaving the project dependent on a single maintainer. This materially increases continuity risk if that maintainer becomes unavailable.
The repository has no security policy. For a Laravel starter application handling authentication, permissions, and one-time passwords, that is a meaningful transparency and vulnerability-reporting gap.
Both workflows were fully analyzed with no audit findings, no untrusted checkouts, no script injection, and all five action references pinned. One workflow grants top-level write permissions, a mild token-scope concern, but no untrusted trigger or sink corroborates a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/chisel Version ^0.1.0 | — | — |
laravel/tinker Version ^3.0 | — | — |
laravel/fortify Version ^1.37.2 | — | — |
laravel/framework Version 13.21.1 | — | — |
laravel/wayfinder Version ^0.1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.