A single maintainer and no repository security policy leave limited visible project support. The package is licensed, documented, tested, and not deprecated, which offsets some of the maintenance concerns.
52%
Total Score
50
78
63
The package has five releases, but none in the last 12 months and the latest release was published in September 2025. This is a meaningful maintenance concern for a relatively young package.
Install-time lifecycle scripts are present, including post-create-project and post-update hooks. These scripts deserve caution because they can run during dependency operations, even though the collected signal does not show malicious behavior.
Only one registry publishing maintainer is listed, which increases continuity risk for a small project. The individual ownership context makes this less concerning than a thin registry list for an organization-backed project, but it remains a limitation.
The artifact contains a full Laravel application alongside the package files, including application configuration and framework scaffolding. That unusual layout makes publication boundaries and what consumers actually install less clear.
The repository is owned by an individual account rather than an organization, so there is no observed organizational backing to offset the single-maintainer risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^2.8 | — | — |
laravel/sanctum Version ^3.3 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
laravel/framework Version ^10.10 | — | — |
wendelladriel/laravel-validated-dto Version ^3.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.