Cached database options for Laravel
66%
Total Score
caution
A first-day release with no commit history and entirely unpinned workflow actions leaves maintenance and build reproducibility unproven.
The package declares a post-autoload-dump install-time script. This is a supply-chain and installation-behavior consideration, but the provided signal does not show that the script is unsafe.
This is the package's first release, published today, so there is no release history or established cadence to demonstrate maturity. That is a meaningful but early-stage concern rather than evidence of abandonment.
The repository has no commits and no active maintainers in the last three months; because the project was created today, this is not proof of a collapse, but sustained maintenance is still unproven.
All 9 of 9 action references are unpinned, weakening build reproducibility. The audit found no high- or medium-severity issues, and the pull_request_target workflow has no untrusted checkout or script-injection sink; top-level write permissions in two workflows remain a mild hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^12.0||^13.0 | — | — |
illuminate/cache Version ^12.0||^13.0 | — | — |
illuminate/console Version ^12.0||^13.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.