Regular releases and two active contributors support ongoing maintenance, with a matching repository, tests, changelog, and security scanning. Workflow permissions, unpinned actions, and a high-confidence bot-condition warning leave meaningful automation hygiene concerns.
74%
Total Score
100
100
50
A post-autoload-dump install-time script is present. This adds installation behavior to review, but the signal does not show that it is unsafe or unusually extensive.
No repository security policy was found, leaving disclosure guidance and security-contact transparency undocumented.
All five workflows were analyzed, but all 11 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection finding, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/prompts Version ^0.1 || ^0.2 || ^0.3 | — | — |
symfony/process Version ^7.0 || ^8.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/filesystem Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.