Its MIT license, clear README, and automated security tooling make the package easy to evaluate. Organization backing helps offset the single-contributor record, but the project remains immature and its workflow setup needs attention.
55%
Total Score
67
100
94
50
Both workflows were analyzed, but all 5 action references are unpinned and one workflow grants top-level write access. The high-confidence bot-conditions finding in dependabot-auto-merge.yml is the most significant issue because actor checks may be spoofable.
This package is only 99 days old and has one release, so there is little release history from which to judge sustained maintenance.
All recent commits came from one contributor. The organization-owned repository provides some ability to hand maintenance off, so this is a concern rather than a severe abandonment signal.
Only one commit was recorded in the last three months, with one active maintainer, providing weak evidence of ongoing maintenance.
No security policy was found in the repository, leaving vulnerability-reporting expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.1.3 || ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.