Track and enforce temporary code and technical debt in Laravel applications.
62%
Total Score
caution
A first-day release has no demonstrated maintenance history, despite tests and organization backing.
This is the package's first release, published today, so there is no release track record yet. That is a real maturity gap, but it is expected for a new project rather than evidence of abandonment.
The repository has no commits and no active maintainers in the last three months, but the package was released today, so this mostly reflects its newness rather than a demonstrated collapse in maintenance.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning is a modest transparency and hygiene gap, not a severe dependency risk on its own.
The repository has no security policy. For a new package this lowers disclosure transparency, though it is not evidence that the package is unsafe.
All three workflows use read-only permissions and the audit found no high- or medium-confidence findings, which is good. However, all 8 analyzed action references are unpinned, leaving workflow supply-chain inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^7.0|^8.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
illuminate/console Version ^13.0 | — | — |
illuminate/support Version ^13.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.