The project has a substantial test-backed repository and release notes for this version. Keep in mind it is still pre-1.0 and its release workflow uses unpinned actions and installs an unlocked package.
78%
Total Score
100
100
88
83
Composer build tooling is present, but no security scanning tool was detected. That is a modest maintenance and review gap rather than evidence of unsafe code.
Version v0.5.6 is not a prerelease, but the project remains below a stable major version. That indicates some API and maturity risk despite the active release cadence.
Both workflows were fully analyzed with no untrusted checkout or script-injection findings. However, all 11 action references are unpinned, and the release workflow has high-confidence low-severity adhoc package installation plus top-level write permissions, creating avoidable supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
enshrined/svg-sanitize Version ^0.22.0 | — | — |
inertiajs/inertia-laravel Version ^3.1 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.