Workbench Companion for Laravel Packages Development
58%
Total Score
caution
A brand-new package has one release and no recorded commits in the last three months, with all workflow actions unpinned.
A post-autoload-dump script runs during installation. This is worth awareness because install-time behavior expands the execution surface, although the signal alone does not show harmful behavior.
This is a brand-new package with one release and no established release cadence, so its maintenance history is not yet demonstrated.
The repository recorded zero commits and zero active maintainers over the last three months. Because the package is only newly released, this may reflect its age, but it leaves maintenance capacity unproven.
No security policy was found in the repository, leaving disclosure and response expectations unclear for consumers.
All six workflows were analyzed with no high-confidence audit findings, and four use read-only permissions. However, all 23 analyzed action references are unpinned and one workflow grants top-level write access, creating a meaningful reproducibility and token-scope hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.2 | — | — |
fakerphp/faker Version ^1.23 | — | — |
symfony/process Version ^7.2 | — | — |
wpstarter/o-canvas Version ^2.0 | — | — |
wpstarter/framework Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.