A clear README, tests, changelog, and release notes make adoption easier. Organization backing helps, but all nine workflow actions are unpinned and recent commits come from one contributor.
76%
Total Score
83
88
100
All 245 recent commits came from one contributor, giving the project a single-person operational dependency. Organization backing helps with handoff potential, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe dependency risk.
Version v0.41.0 is not a stable major release, but it is not a prerelease and recent releases contain no prerelease versions. The pre-1.0 status is a compatibility caveat rather than an abandonment signal.
The audit analyzed both workflows completely and found no untrusted checkout or script injection, but all nine action uses are unpinned, one workflow grants top-level write access, and test.yml installs a package outside a lockfile. These are workflow hygiene concerns, with no high- or medium-severity finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.