Risky to adopt despite strong maintenance and repository evidence: the name signal says it borrows the identity of spatie/laravel-ignition, so consumers may have intended that package instead. The project is otherwise active, documented, licensed, and backed by a matching organization repository.
48%
Total Score
100
83
67
The indicator reports that this package borrows the identity of spatie/laravel-ignition, which has far more downloads and stable releases, and is not described as a fork. Consumers most likely wanted spatie/laravel-ignition, making this a severe package-selection risk.
Composer build tooling is present, but no security scanning tools were detected. The missing scanner is a transparency gap, though it does not outweigh the repository's other maintenance evidence.
The repository has no published security policy. That weakens vulnerability-reporting transparency, although it is not evidence that the package is unmaintained.
All three workflows lack top-level permissions declarations, so their effective token access is less explicit than ideal. No workflow requests top-level write permissions, which partly limits the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.