Queopius Sentinel — HTTP Security & HTTPS Hardening for Laravel
23%
Total Score
critical
Package is marked abandoned, has no commits in three months, and points to a repository that does not identify this package.
Packagist marks the entire package as abandoned rather than only this release; although a replacement is listed, it is the same package name, so the deprecation remains a severe adoption risk.
The repository recorded zero commits and zero active maintainers over the last three months, which is a meaningful maintenance and abandonment concern despite the recent release history.
The linked repository is named sentinel rather than shield and does not mention this package in its README, raising concern that the source repository may not actually belong to this release.
All 12 analyzed action references are unpinned, leaving workflow dependencies exposed to unexpected upstream changes. The audit found no untrusted checkout, script injection, or high-severity findings, which limits the impact to workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
illuminate/routing Version ^11.0|^12.0|^13.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.