Tests, a matching repository, and release notes improve transparency. Composer lifecycle hooks and the lack of a security policy add smaller oversight concerns.
57%
Total Score
50
100
81
67
There were no commits and no active maintainers in the three months measured. Combined with no registry releases since 2020, this indicates effectively stalled maintenance.
The package defines post-autoload-dump, post-create-project-cmd, and post-root-package-install scripts. These are relevant installation behavior to inspect, but their presence alone does not establish a health or safety defect.
Only two releases were published, both in November 2020, with none in the last 12 months. This is a substantial maintenance concern for a starter template, although the repository was pushed more recently.
There are no new or closed issues in the measured month and no merged pull requests, while 24 pull requests remain open. This suggests limited ongoing project management.
Composer is used as a build tool, but no security scanning tool is configured. The missing scanning is a modest transparency gap rather than evidence of abandonment on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^3.0 | — | — |
laravel/tinker Version ^2.5 | — | — |
tymon/jwt-auth Version ^1.0.1 | — | — |
fideloper/proxy Version ^4.2 | — | — |
guzzlehttp/guzzle Version ^7.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.