Its workflows use six unpinned actions and the repository has no security policy. A recent release, 33 commits in three months, tests, and release notes provide useful evidence of ongoing work.
68%
Total Score
63
88
50
Four Composer lifecycle scripts run during installation or updates. These are common for a Laravel starter kit but still create additional install-time behavior for consumers.
Only one registry account can publish releases. The linked repository is also owned by an individual, so there is no organizational backing shown to offset the concentrated publishing responsibility.
The repository owner is an individual rather than an organization, so the project lacks the handoff capacity that can mitigate a concentrated maintainer base.
All 33 recent commits came from one contributor, leaving maintenance dependent on a single person and increasing continuity risk.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0.2 | — | — |
laravel/framework Version ^13.25 | — | — |
livewire/livewire Version ^4.4.0 | — | — |
intervention/image Version ^4.2.1 | — | — |
opcodesio/log-viewer Version ^3.24.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.