Usable with caveats: the package is licensed, tested, documented, and backed by a matching repository with security tooling. However, it has had no release for about 13 months and no commits in the last 3 months, so maintenance may be slowing.
68%
Total Score
50
89
75
The package has seven releases over roughly two years, but no releases in the last 12 months; the resulting maintenance gap is a genuine concern for a Laravel integration package.
The repository recorded zero commits and zero active maintainers during the last 3 months. Although it was pushed in December 2025, the current inactivity raises abandonment risk.
The repository has zero stars and forks and one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little external evidence of community adoption or review.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though the repository does provide security scanning tools.
Two workflows declare top-level write permissions, which grants broader automation access than the one read-only workflow. This is a modest workflow-hygiene concern, but no dangerous workflow behavior was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0 || ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.