Clear documentation, an MIT license, and organization ownership make adoption easier. The small registry maintainer list is unsurprising for an organization-backed project.
78%
Total Score
100
100
100
50
The package runs a post-autoload-dump lifecycle script during installation. This is worth awareness because install-time code executes automatically, but the signal alone does not show an unsafe operation.
No SECURITY.md policy was found in the linked repository. This is a transparency gap for reporting vulnerabilities, though it does not outweigh the project's active maintenance evidence.
All eight workflows were analyzed, but all 23 action references are unpinned, four workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection path was found, keeping this as a hygiene caution rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.0|^13.0 | — | — |
livewire/livewire Version ^4.0 | — | — |
tallstackui/tallstackui Version ^3.2.1 | — | — |
phpoffice/phpspreadsheet Version ^5.3 | — | — |
spatie/laravel-model-info Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.