The repository includes tests, a changelog, matching package files, and Dependabot, but its automation uses broad permissions and an unsafe bot check. Pin 2.4 only when its current behavior is acceptable, since ongoing maintenance is uncertain.
54%
Total Score
75
90
50
The package is 776 days old with 10 releases but no releases in the last 12 months, indicating that maintenance may have stopped. The stable 2.4 release and documented release notes provide some transparency but do not offset the prolonged inactivity.
The repository recorded zero commits and zero active maintainers during the last three months, reinforcing the risk that defects or compatibility issues may remain unaddressed.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. Dependabot and repository tooling provide limited compensation but do not replace a maintainer-facing policy.
All 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. There are no untrusted checkouts or script-injection findings, so this is a meaningful hygiene and supply-chain caution rather than a severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0 | — | — |
illuminate/database Version ^8.0|^9.0 | — | — |
spatie/laravel-package-tools Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.