Tests, an active repository, and pinned workflow actions provide useful support. The project is still young and has no published security policy, while most recent commits come from one contributor. Expect a less proven dependency.
70%
Total Score
83
94
50
The package is only 54 days old and has one release, so its maintenance record and compatibility history are limited.
Two contributors are active, but one accounts for 76% of recent commits, leaving maintenance capacity concentrated despite the organization-owned project.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in an application with an external API.
Both workflows were analyzed successfully, all five action references are pinned, and no audit findings or untrusted-code sinks were found. One workflow grants top-level write access, a mild permissions concern without an untrusted trigger.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0 | — | — |
laravel/sanctum Version ^4.3 | — | — |
laravel/framework Version ^13.17 | — | — |
laravel/wayfinder Version ^0.1.14 | — | — |
inertiajs/inertia-laravel Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.