Shared Laravel + Inertia v3 + React package for Shopify App Bridge toasts and Polaris s-banner notices
62%
Total Score
caution
Usable with caveats: a high-confidence workflow warning and all commits from one contributor raise maintenance and release-process risk.
The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow and 13 of 19 action references are unpinned; the low-confidence cache-poisoning finding is hygiene rather than a standalone severe risk.
A post-autoload-dump script is present, which is common Composer package behavior but adds install-time execution that consumers should understand.
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not visibly offset by organizational backing.
The package is only 32 days old and has two releases, so there is too little history to establish long-term maintenance reliability.
All seven recent commits came from one contributor, leaving the project dependent on a single maintainer for continuity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
inertiajs/inertia-laravel Version ^3.0.5 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.