The repository is not archived and includes tests, a changelog, and a security policy. Workflow references are all unpinned, weakening build reproducibility despite no detected dangerous workflow findings.
57%
Total Score
94
83
The latest registry release was nearly six years ago, with no releases in the last 12 months. This is a substantial maintenance and compatibility concern for a Laravel integration package.
All four workflows were analyzed successfully and no dangerous triggers, untrusted checkouts, script injection, or audit findings were detected. However, all 11 action references are unpinned, leaving the workflow supply chain less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.9 | — | — |
illuminate/events Version ^8.0 | — | — |
illuminate/console Version ^8.0 | — | — |
illuminate/support Version ^8.0 | — | — |
illuminate/contracts Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.