User to Team associations for the Laravel 5 Framework
82%
Total Score
67
100
94
80
The repository is owned by the user account mpociot rather than an organization, so the two-account registry maintainer list does not receive organization-backing compensation; this is a modest bus-factor concern rather than a severe risk.
There were zero commits and zero active maintainers in the last 3 months. Although a release was published on the assessment date, the absence of recent commit activity is a genuine maintenance-continuity concern.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap that is relevant but not severe on its own.
The repository has no security policy, reducing transparency around vulnerability reporting and response expectations.
All three workflows lack top-level token permissions declarations, although none declares top-level write access and one uses job-level permissions; explicit least-privilege configuration would be preferable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.