This is a generally healthy and actively maintained release: the package has existed since 2019, published 7 releases in the last 12 months, is on a stable non-prerelease version, is not deprecated, and has a matching repository with tests, CI, Dependabot, and recent activity. The main concerns are that all three commits in the last 3 months came from one contributor, the repository lacks a security policy, and some workflows use broad or undeclared token permissions; these warrant review but do not indicate abandonment or make the package unfit to depend on.
78%
Total Score
60
100
100
70
One of four workflows uses pull_request_target, specifically the Dependabot auto-merge workflow. No untrusted checkout or script-injection patterns were detected, so this is a limited workflow-risk concern rather than a severe finding.
Only one account has registry publish access. This is a modest publishing-resilience concern, though the repository's recent release and commit activity show that the maintainer is active.
The repository is owned by a user account rather than an organization, so there is no visible organizational maintenance cushion to offset the concentrated contributor base.
All 3 recent commits came from one contributor, with a 100% top-contributor share and only one recent contributor, creating meaningful continuity risk for a user-owned project.
The repository recorded 3 commits in the last 3 months with one active maintainer, demonstrating recent activity but only modest maintenance throughput.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.