A single maintainer carries all 26 recent commits, while workflow actions are all unpinned and no security policy is published. Recent releases, tests, release notes, licensing, and active repository work provide useful counterweight.
72%
Total Score
75
50
100
50
The application declares 34 runtime dependencies and nine development dependencies, including many framework and project-specific components. This is substantial integration surface for a web UI, but the signal does not show an abnormal or unsafe dependency pattern.
Four install or update lifecycle scripts run during Composer operations, increasing install complexity and execution exposure for a framework application. No provided signal shows these scripts are unsafe, so this is a moderate hygiene concern rather than a severe risk.
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
One contributor made all 26 commits in the last 3 months, so maintenance depends entirely on a single active person and has a meaningful continuity risk.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented for this security-sensitive web application.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0 | — | — |
laravel/sanctum Version ^4.3 | — | — |
filament/filament Version ^5.0 | — | — |
laravel/framework Version ^13.8 | — | — |
livewire/livewire Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.