Create a static site bundle from a Laravel app
58%
Total Score
50
89
50
The package has 32 releases over about 13 months and five releases in the last year, but the median interval is 0 days, indicating bursty rather than consistently demonstrated maintenance.
No commits and no active maintainers were observed in the last 3 months, which weakens confidence that defects and compatibility changes will be addressed promptly.
The repository has only 1 star, no forks, and no watchers, giving little independent evidence of broad review or community support.
The repository has no published security policy, leaving vulnerability reporting and response expectations undocumented.
All 10 analyzed action references are unpinned, and a high-confidence bot-conditions finding reports potentially spoofable actor checks in the Dependabot auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection finding, so this is a hygiene and workflow-integrity concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8.1 | — | — |
spatie/crawler Version ^8.4.4 | — | — |
illuminate/http Version ^10.0|^11.0|^12.0 | — | — |
symfony/console Version ^6.4.2|^7.0 | — | — |
symfony/process Version ^6.4.2|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.