This release appears suitable for dependency use and has a generally healthy maintenance profile: it is a stable major release from a package with more than five years of history, recent releases, an active non-archived repository, clear documentation, a changelog, repository tests, a license file, and no install-time lifecycle scripts. The main reservations are that repository commit activity shows no commits or active maintainers in the last three months, the registry has only one publishing maintainer, and the repository lacks a security policy, security-scanning tooling, and explicit workflow token permissions. These are meaningful transparency and maintenance-process gaps, but they do not outweigh the concrete evidence of ongoing releases, organization backing, repository alignment, and test coverage.
78%
Total Score
63
100
89
75
Only one registry account has publish access, which creates a limited publishing-persona and bus-factor concern. However, the linked repository is organization-owned, so this is a caution rather than a severe project-backing risk.
The repository recorded 0 commits and 0 active maintainers in the last three months. Although recent releases and a very recent push provide some compensation, the absence of observed short-term development activity is a maintenance caution.
There are no open issues or pull requests and no issue or pull-request activity in the last month. The clean queue is positive, but the lack of recent interaction provides limited evidence of active community maintenance.
The repository has 1 star, 0 forks, and 0 watchers. This indicates limited adoption or visibility, but popularity is supporting evidence only and does not outweigh the package's release, testing, and repository-health signals.
Composer build tooling is present, but no security-scanning tools are configured. The missing scanning process is a modest supply-chain transparency gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.