Documentation, tests, release notes, and security tooling make the project easy to evaluate. Its limited ownership and workflow hygiene leave more maintenance and publishing risk than a mature dependency.
55%
Total Score
50
94
50
The package declares four install or update lifecycle scripts, including post-autoload-dump and post-update-cmd. These may be normal for a Laravel application template but increase installation and update complexity.
One registry maintainer, Ashraf, publishes the package. With project backing identified as an individual user rather than an organization, this creates a thin operational base.
This is the only release, published 14 months ago, with no releases in the last 12 months. That leaves maintenance continuity unproven for a package intended as a production backend foundation.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's single-release history. The absence of recent activity raises abandonment risk, although the project is still new.
The repository has no security policy. For a backend boilerplate advertising authentication and permissions features, the lack of a documented vulnerability-reporting path reduces transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/scout Version ^10.17 | — | — |
predis/predis Version ^3.1 | — | — |
dedoc/scramble Version ^0.12.26 | — | — |
laravel/tinker Version ^2.10.1 | — | — |
laravel/passport Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.