Laravel bridge for Rapira: classic, worker and dispatcher modes on top of Laravel Octane
68%
Total Score
caution
A brand-new package with only two same-day releases and no recent commit history, despite good tests, documentation, and release hygiene.
The package is less than one day old with only two releases, both published within about 10 hours. This provides too little history to demonstrate sustained maintenance, though the rapid second release shows active initial work.
The repository reports zero commits and zero active maintainers in the last three months, but the package itself is only about 10 hours old. This limits evidence of durable maintenance rather than proving abandonment.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is less serious for a brand-new package with no other security-policy evidence.
Version 0.1.1 is not a stable major release, indicating an early-stage API and greater compatibility risk for adopters.
All four workflows were analyzed with no audit findings, untrusted checkouts, or script injections. However, all nine action references are unpinned and one workflow grants top-level write permissions, creating workflow-reproducibility and token-scope hygiene concerns without an observed exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/octane Version ^2.13 | — | — |
rapira/contract Version ^0.9 | — | — |
laravel/framework Version ^11.0 || ^12.0 || ^13.0 | — | — |
symfony/http-foundation Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.