A small contributor base and broad workflow permissions leave some operational risk. The package is clearly licensed, documented, tested in its repository, and backed by an organization.
78%
Total Score
100
94
50
The package uses a post-autoload-dump install lifecycle script. This adds some installation complexity, but the signal alone does not show harmful behavior or unusual risk.
Composer build tooling is used, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy. That makes vulnerability reporting and response expectations less clear for users of a package that handles editor content and image uploads.
Both workflows were analyzed with no auditor findings or untrusted checkout/script-injection sinks, but all 5 action references are unpinned and one workflow grants top-level write permissions. These are workflow hygiene and containment concerns, not severe risks on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^3.4 | — | — |
intervention/image Version ^3.11 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.