Create a static site bundle from a Laravel app
48%
Total Score
100
89
50
The package is reported to borrow the identity of spatie/laravel-ray, which has far more downloads and stable releases; this strongly suggests consumers may have intended that other package despite zero artifact overlap.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
All 10 analyzed GitHub Actions references are unpinned, creating reproducibility and action-substitution risk. The pull_request_target workflow has no untrusted checkout or script-injection sink, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8.1 | — | — |
spatie/crawler Version ^9.1 | — | — |
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
symfony/console Version ^6.4.2|^7.0|^8.0 | — | — |
symfony/process Version ^6.4.2|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.