Its documentation, release notes, licensing, and recent project activity are in good shape. The small contributor pool and lack of repository security scanning leave limited independent review.
84%
Total Score
100
100
88
50
A post-autoload-dump install lifecycle script runs during Composer installation, adding execution behavior that deserves attention even though no harmful behavior is established by this signal alone.
Composer build tooling is present, but no security scanning tools were detected, leaving a repository-hygiene gap.
No repository security policy was found, reducing transparency for reporting and handling vulnerabilities.
Version v0.1.4 is not yet at a stable major version, so API or behavior changes remain more likely despite the release being marked non-prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.9|^0.10|^0.11 | — | — |
laravel/framework Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.