Healthy and reasonable to depend on. It has regular releases, a maintained organization-owned repository, current release notes, tests in the source repository, and no deprecation or archive status. Review the repository's broad workflow permissions and lack of a security policy before adopting it in a high-risk environment.
82%
Total Score
100
100
100
63
One workflow uses pull_request_target, which can require careful review, but the analyzed workflows show no untrusted checkout or script-injection findings. The residual workflow risk warrants caution rather than a severe health penalty.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a package that exposes remote command execution functionality.
One workflow has top-level write permissions and another lacks top-level permissions declarations, reducing clarity and least-privilege assurance for automation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.