The package has clear licensing, release notes, repository tests, and organization backing. Recent repository activity is paused, and the workflows use unpinned actions and a high-confidence unpinned container image.
72%
Total Score
83
100
100
50
The repository had zero commits and zero active maintainers in the last three months, a real sign that maintenance has slowed even though the repository was pushed recently.
The repository has no security policy, leaving vulnerability reporting guidance undocumented; this is a transparency gap, but it is not evidence of abandonment by itself.
All 12 action references are unpinned, and the audit found a high-confidence unpinned container image; the pull_request_target workflow has no untrusted checkout or script-injection sink, limiting the risk to workflow hygiene rather than a severe dependency verdict.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10373 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. spatie/laravel-ignition is vulnerable to Generation of Error Message Containing Sensitive Information in versions 0.0.1 - 2.4.1. | 0.0.1 - 2.4.1 | Low |
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.72|^3.0 | — | — |
spatie/ignition Version ^1.16 | — | — |
symfony/console Version ^7.4|^8.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
symfony/var-dumper Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.