The in-app notification inbox Laravel never shipped: a header bell, an inbox page and per-type preferences, on top of the database notification channel.
67%
Total Score
caution
A brand-new package has no observed commit history yet, and every GitHub Actions dependency is unpinned.
The package is brand new, released only twice on the same day, so there is not enough history to demonstrate sustained maintenance or release stability.
No commits or active maintainers were observed in the last three months. Because the package is only hours old, this is more a lack of maintenance evidence than proof of abandonment, but it still limits confidence.
The repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a verdict, but it provides no external maturity signal for this newly published package.
Both workflows were analyzed successfully with no untrusted checkouts, injection findings, or high-severity audit results. However, all 8 action references are unpinned and one workflow grants top-level write permissions, creating a manageable automation-hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.4.1|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.