The package includes tests, release notes, a clear license, and a security policy. Its beta status and fully unpinned workflow actions add adoption and build-reproducibility caveats, while organization backing offsets concentrated commits.
78%
Total Score
100
94
83
v7.0.0-beta.6 is a prerelease, so API or behavior changes are more likely than for a stable release. The broader release history is active, which partly offsets the maturity concern.
All six workflows use read-only permissions, have no detected untrusted checkouts, script injection, or audit findings, and the audit completed fully. However, all 17 analyzed action references are unpinned, weakening build reproducibility and supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-694446 power-components/livewire-powergrid is vulnerable to Path Traversal in versions 0.0.1 - 6.10.5. | 0.0.1 - 6.10.5 | High |
AIKIDO-2026-888106 power-components/livewire-powergrid is vulnerable to SQL Injection in versions 6.0.0 - 6.10.3. | 6.0.0 - 6.10.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
livewire/blaze Version ^1.0 | — | — |
laravel/prompts Version ^0.1|^0.2|^0.3 | — | — |
livewire/livewire Version ^4.0 | — | — |
power-components/turbine Version ^0.9.0 | — | — |
power-components/partials Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.