Artisan Tinker in your browser
38%
Total Score
unhealthy
Risky: no release or commit activity since September 2020, despite a documented and licensed package.
The package has had no release in about six years, with zero releases in the last 12 months. Its 29 historical releases show prior activity but do not offset the prolonged stoppage.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with long-term abandonment risk.
There were no new issues, closed issues, or pull requests in the last month, and no pull requests were open; this reinforces the absence of current project activity.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no community signal to compensate for the inactivity.
All five action references are unpinned, and the audit found a high-confidence unpinned container image. The workflows avoid untrusted triggers and script injection, so this is a hygiene concern rather than a severe supply-chain finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^1.0|^2.0 | — | — |
illuminate/cookie Version ^5.8|^6.0|^7.0|^8.0 | — | — |
illuminate/session Version ^5.8|^6.0|^7.0|^8.0 | — | — |
illuminate/support Version ^5.8|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.