A clear README, tests, and MIT declaration make adoption easier, while install-time scripts deserve review for a starter kit. No security scanning or policy is documented, so transparency is weaker than its active repository suggests.
72%
Total Score
75
79
50
Four install and update lifecycle scripts run automatically, which is expected for a Composer starter kit but increases the amount of package behavior to inspect before use.
The repository is owned by an individual user rather than an organization, so the concentrated contributor activity is not offset by visible organizational backing.
The package is 42 days old and has only one release, so there is little release history from which to judge long-term stability.
Two contributors are active, but one accounts for about 91% of the last three months' commits, leaving maintenance highly concentrated.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful verification gap for a package that installs application code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0 | — | — |
nckrtl/waymaker Version ^0.2.3 | — | — |
laravel/framework Version ^13.0 | — | — |
laravel/wayfinder Version ^0.1 | — | — |
spatie/laravel-csp Version ^3.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.