Core utilities for Laravel apps: standardized API responses, request ID middleware, and CLI helpers.
58%
Total Score
caution
Active development is offset by a risky release workflow, concentrated ownership, and unusually compressed release history.
Both workflows were analyzed with read-only permissions, but the release workflow combines workflow_run with an untrusted checkout, and the audit also found a high-confidence archived action plus two of eight unpinned actions.
The repository is owned by an individual user rather than an organization, so there is no organizational handoff capacity to offset the concentrated contributor base.
The registry shows 110 releases in the last 12 months, but all are recorded within one day with a zero-day median interval, making the release history unusually compressed and harder to interpret as established cadence.
Two contributors are active, but the top contributor accounts for about 67% of recent commits, leaving maintenance somewhat concentrated.
The repository has one star and no forks or watchers, which provides little external validation, though popularity is only supporting evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.0|^3.0 | — | — |
laravel/framework Version ^12.0|^13.0 | — | — |
intervention/image Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.