Healthy and suitable to depend on. It has a clear license, thorough documentation, tests, recent release notes, active organizational backing, and no deprecation or archive status. Maintenance is currently concentrated in one contributor, and the repository lacks a security policy and explicit workflow permissions.
82%
Total Score
67
100
100
80
All recent commit activity came from one contributor, creating a continuity risk. The organization-owned repository provides some capacity to hand maintenance off, so this is a caution rather than a severe risk.
There was one commit in the last three months, which demonstrates recent activity but is a thin maintenance pace for a dependency.
No security policy is present in the repository, leaving vulnerability reporting guidance unclear. This is a transparency gap, though the package's other maintenance evidence is positive.
The only workflow does not declare top-level token permissions, so its GitHub Actions privileges are less explicit than recommended. No write permissions were observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0|^11.0|^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.