The package is well documented and tested, with a stable v1 release and organizational backing. Its modest adoption, absent security policy, and unpinned workflow references leave some review work for adopters.
78%
Total Score
100
100
83
83
There have been 8 releases in 141 days, although the latest release was about 3 months ago and the releases were concentrated into short intervals. This supports a real release process but does not yet establish long-term continuity.
The repository has 6 stars, 1 fork, and 0 watchers. This indicates limited adoption evidence, but popularity is supporting context and does not outweigh the maintenance signals.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning automation is a hygiene gap rather than evidence of abandonment.
The repository has no SECURITY.md or other detected security policy. For a package that performs image discovery and downloading, this reduces vulnerability-reporting transparency.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 5 action references are unpinned, leaving avoidable supply-chain drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.6.5 | — | — |
illuminate/bus Version ^13.0 | — | — |
illuminate/log Version ^13.0 | — | — |
illuminate/http Version ^13.0 | — | — |
laravel/sanctum Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.