Three active contributors and frequent releases provide strong maintenance capacity. The repository lacks a security policy, and its workflows need tighter action pinning and credential boundaries.
82%
Total Score
100
94
67
Composer build tooling is present, but no security scanning tools were detected, leaving a modest verification gap.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package with substantial runtime dependencies.
All eight workflows were analyzed, but all 22 action references are unpinned; two high-confidence secrets-inherit findings and an adhoc package install add workflow supply-chain hygiene concerns. A workflow_run job also performs an untrusted checkout, though no script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^4.2|^5.3 | — | — |
laravel/scout Version ^10.14 | — | — |
lcobucci/clock Version ^2.0|^3.2 | — | — |
tormjens/eventy Version ^0.8 | — | — |
illuminate/queue Version ^12.50|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.