Easily access proxies from your buyproxies account within your Laravel application
58%
Total Score
50
100
88
50
One workflow uses pull_request_target for Dependabot auto-merging, which carries elevated automation risk, although no untrusted checkout or script-injection pattern was detected.
The registry namespace and repository owner match, but the project is backed by an individual user rather than an organization, so the single-maintainer context offers limited continuity.
This is the only release, published about three and a half years ago, with no releases in the last 12 months. That substantially increases the risk that maintenance has stalled.
The repository recorded zero commits and zero active maintainers in the last three months. For a package with only one historical release, this is a meaningful abandonment concern.
There are three open pull requests and none were merged in the last month, suggesting that available changes may not be receiving timely attention.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0.1 | — | — |
illuminate/contracts Version ^8.0|^9.0|^10.0 | — | — |
spatie/laravel-package-tools Version ^1.12.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.