Documentation and licensing are solid, and the repository has tests and a security policy. Recent commit activity is absent; adopt toneflix/laravel-dbconfig instead.
20%
Total Score
75
88
100
Packagist marks the entire package as abandoned and provides toneflix/laravel-dbconfig as its replacement. This is a direct adoption risk even though the assessed release is stable.
The repository recorded zero commits and zero active maintainers in the last three months. That weakens evidence of ongoing maintenance and adds abandonment risk.
All five workflows were analyzed, but all 13 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. These are meaningful workflow-hygiene concerns, although no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0|^13.0 | — | — |
toneflix/laravel-fileable Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.