The small maintainer base and quiet recent development increase abandonment risk. The package is well documented, tested in its repository, licensed, and not deprecated, but workflow controls need tightening.
62%
Total Score
38
100
94
50
The repository recorded zero commits and zero active maintainers in the last three months, a material maintenance and abandonment risk.
All 12 action references are unpinned, three workflows grant top-level write access, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not independently severe.
A post-autoload-dump install script adds execution during dependency installation, increasing supply-chain exposure compared with a package without lifecycle hooks.
One registry maintainer creates a thin publishing base, although the linked repository is owned by the same individual, so the ownership is consistent rather than unexplained.
The registry namespace and repository owner match, but the project is backed by an individual rather than an organization, limiting visible maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/pulse Version ^1.0 | — | — |
laravel/framework Version ^10.0|^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.