Server-side analytics for Laravel that follows the full funnel from visit to registration to payment, attributed to the channel that drove it. Revenue, MRR, churn and ad-spend profit (ROAS/CAC) per channel. GDPR compliant, ad-blocker proof.
72%
Total Score
caution
Usable with caveats: active maintenance is offset by a license mismatch and risky workflow hygiene.
The manifest declares MIT, but the artifact license file is detected as GPL-3.0; although a license file is present, the unresolved mismatch creates adoption and compliance uncertainty.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a package that handles application tracking data.
The audit completed all 5 workflows and found a high-confidence bot-conditions issue; all 12 action references are unpinned, and 3 workflows grant top-level write permissions. The pull_request_target workflow has no untrusted checkout or script-injection finding, so these are workflow hygiene and review risks rather than a demonstrated exploit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.