The package has clear documentation, tests, release notes, and a modest dependency set. Its single active contributor and unpinned workflow actions leave some maintenance and build-reproducibility risk.
82%
Total Score
50
100
100
83
The registry namespace and repository are owned by the same individual, so the package has coherent ownership but no organizational maintenance buffer. This reinforces the single-contributor concern without indicating abandonment by itself.
All recent commits came from one contributor, giving the project a 100% top-contributor share. Because the backing owner is an individual rather than an organization, this creates a real continuity risk.
The repository recorded one commit in the last three months from one active maintainer. The recent release offsets the low volume, but the limited activity provides only modest evidence of ongoing maintenance capacity.
The repository has no published security policy. For a Laravel broadcasting library handling API credentials, this is a minor transparency gap, though it is partly offset by Dependabot and the dedicated security tests shown in the package tree.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 9 analyzed action references are unpinned, which weakens build reproducibility and leaves a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8.75|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.