A Laravel client for the Image Forge service.
72%
Total Score
caution
All nine workflow actions are unpinned, with a high-confidence template-injection finding.
The package is less than a day old with 3 releases, including this version, so there is little evidence yet of sustained maintenance. The rapid initial release activity is a modest compensating signal, not proof of long-term stability.
The repository reports 0 commits and 0 active maintainers over the last 3 months, but the package itself is newly created, so this is limited evidence of abandonment rather than a strong negative conclusion.
Composer build tooling is present, but no security-scanning tools were detected. That leaves a gap in the project's visible security hygiene.
No security policy was found in the repository. This reduces vulnerability-reporting transparency, although it does not by itself indicate unsafe code.
All 9 of 9 action references are unpinned, and the audit found a high-confidence template-injection issue in update-changelog.yml. No untrusted checkout or script-injection path was reported, so this is a meaningful hygiene concern rather than a severe standalone dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^12.0 | — | — |
illuminate/routing Version ^12.0 | — | — |
illuminate/support Version ^12.0 | — | — |
illuminate/database Version ^12.0 | — | — |
illuminate/contracts Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.