Its documentation, tests, MIT license, and matching repository make the package transparent to integrate. The workflow references are mostly unpinned and the project has no published security policy, adding maintenance risk.
38%
Total Score
79
75
The package has 43 releases since 2017, but none in the last 12 months; its latest release was in March 2020, more than six years ago. This is strong evidence of abandonment for an application-facing Laravel package.
The linked repository is not archived, which is a compensating sign, but its last push was in March 2020 and does not offset the prolonged release inactivity.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package that provides an administrative web interface.
All four workflows were analyzed without high-confidence findings or untrusted-trigger sinks, but 10 of 11 action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.5 | — | — |
league/flysystem Version ~1.0.41 | — | — |
illuminate/support Version ~5.5|~6.0 | — | — |
intervention/image Version ^2.4 | — | — |
larapack/voyager-hooks Version ~1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.