Clear documentation, tests, and release notes make integration easier. Workflow permissions and unpinned actions leave modest supply-chain hygiene gaps.
68%
Total Score
75
100
94
83
No commits and no active maintainers were recorded in the past three months, which is a meaningful maintenance concern despite the recent release and merged pull requests.
Composer and Make tooling are present, but no security scanning tools were detected, leaving a modest verification gap.
The repository has no security policy, reducing transparency about how vulnerability reports are handled.
All five action references are unpinned, and two release workflows grant top-level write permissions; the audit also found a high-confidence low-severity ad hoc package installation. No untrusted checkout or script-injection paths were found, limiting the risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^4.0 | — | — |
laravel/framework Version ^12.0 | — | — |
whilesmart/eloquent-roles Version * | — | — |
cviebrock/eloquent-sluggable Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.