Version 5.11.0 appears to be a healthy dependency: the package has a long release history, frequent recent releases, stable-version status, active maintenance, and strong organization backing from MongoDB. The linked repository is not archived, matches the package, includes tests and extensive CI/tooling, and shows recent activity from five contributors with no severe concentration risk. The main reservations are the absence of a repository security policy, incomplete top-level GitHub Actions permission declarations, and a pull_request_target workflow; these are transparency and workflow-hygiene concerns rather than evidence of abandonment. The artifact itself omits a README and tests, but repository tests and GitHub Releases compensate for that packaging gap.
91%
Total Score
100
100
100
70
One of eight workflows uses pull_request_target, which warrants review because that trigger can expose elevated repository context, although there are no detected untrusted checkouts or script-injection patterns.
No SECURITY.md or equivalent security policy was found, reducing vulnerability-reporting transparency for a widely used dependency.
Seven of eight workflows lack top-level permissions declarations, although no workflow has top-level write permissions and some jobs use explicit or read-only permissions; the incomplete least-privilege declaration remains a hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-124430 mongodb/laravel-mongodb is vulnerable to NoSQL Injection in versions 1.2.0 - 5.10.0. | 1.2.0 - 5.10.0 | High |
AIKIDO-2026-552268 mongodb/laravel-mongodb is vulnerable to NoSQL Injection in versions 4.0.0 - 5.10.0. | 4.0.0 - 5.10.0 | High |
AIKIDO-2026-633941 mongodb/laravel-mongodb is vulnerable to NoSQL Injection in versions 1.0.0 - 5.10.0. | 1.0.0 - 5.10.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
mongodb/mongodb Version ^1.21|^2 | — | — |
illuminate/cache Version ^12|^13.0 | — | — |
illuminate/events Version ^12|^13.0 | — | — |
illuminate/support Version ^12|^13.0 | — | — |
illuminate/database Version ^12.51|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.