A single active contributor limits handoff capacity, and the project has no published security policy. Stable releases, tests, documentation, and MIT licensing provide useful counterweight.
61%
Total Score
50
100
50
All six recent commits came from one contributor, leaving maintenance and review capacity concentrated in a single person.
Six commits in the last three months show ongoing work, but activity is modest and comes from only one active maintainer.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All 11 analyzed action references are unpinned, and the audit found a high-confidence template-injection issue in spotify-vibe-check.yml. No pull_request_target or workflow_run trigger was observed, so this is a workflow hygiene concern rather than a standalone critical risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.1 | — | — |
laravel/mcp Version ^0.5.9 | — | — |
illuminate/http Version ^12.17 | — | — |
laravel/prompts Version ^0.3 | — | — |
php-tui/php-tui Version ^0.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.