Healthy and actively maintained, with a strong release cadence and substantial recent development. The main caveat is that one contributor made about 93% of recent commits, alongside some workflow-permission and security-documentation gaps.
86%
Total Score
90
50
100
50
One workflow uses pull_request_target, which warrants review because it can run with elevated repository context, but no untrusted checkouts or script-injection patterns were detected.
The package has 32 runtime dependencies, including significant Laravel, database, search, mail, and UI integrations; this is substantial complexity but consistent with a full ERP package rather than an unexplained dependency load.
One contributor made about 93% of the 389 recent commits, creating a real continuity risk; three additional contributors were active, and organization ownership provides some ability to hand maintenance off.
No repository security policy was found, leaving vulnerability-reporting guidance undocumented for a package with substantial application functionality.
Three workflows request top-level write permissions and two omit top-level permissions, which is broader or less explicit than ideal for CI safety; the remaining workflows include read-only or job-level permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dompdf/dompdf Version ^3.1.6 | — | — |
laravel/scout Version ^11.4 | — | — |
nesbot/carbon Version ^3.13 | — | — |
laravel/reverb Version ^1.11 | — | — |
laravel/sanctum Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.