The package is documented and licensed, with a stable release and no install-time scripts. The repository has no security scanning, and its two workflow actions are unpinned, adding avoidable maintenance risk.
45%
Total Score
0
81
67
There have been no releases in the last 12 months, and the latest release was published in March 2023, about 3 years and 6 months ago. The 51-release history shows prior activity but does not offset the prolonged recent silence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long gap since the latest release and indicating a substantial abandonment risk.
Composer is used as the build tool, but no security scanning tools are configured. That leaves an additional assurance gap in a security-sensitive package.
The repository has no security policy. For a package implementing authentication, tokens, permissions, and encryption-related functionality, this is a transparency and maintenance gap.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned. The missing top-level permissions block is acceptable on its own and is not a severe issue here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.1 | — | — |
illuminate/support Version ^8.0 | ^9.0 | ^10.0 | — | — |
illuminate/database Version ^8.0 | ^9.0 | ^10.0 | — | — |
illuminate/contracts Version ^8.0 | ^9.0 | ^10.0 | — | — |
goldspecdigital/laravel-eloquent-uuid Version ^8.0 | ^9.0 | ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.