A CMS like modular Laravel starter project.
82%
Total Score
83
94
75
Two contributors are active, but the primary maintainer made about 89% of recent commits, leaving maintenance dependent on one person.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest assurance gap for a project with application dependencies.
The only workflow was fully analyzed with no dangerous triggers or findings, but all four action references are unpinned, weakening build reproducibility and update control.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-26159 nasirkhan/laravel-starter is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 11.11.0. | 0.0.0 - 11.11.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/tinker Version ^3.0 | — | — |
laravel/framework Version ^13.0 | — | — |
laravel/socialite Version ^5.0 | — | — |
livewire/livewire Version ^4.0 | — | — |
intervention/image Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.