The package includes tests, a clear README, recent releases, and security scanning. Its small maintenance base and unpinned workflow actions leave more reliance on the publisher than a mature dependency.
68%
Total Score
50
100
50
The repository is owned by a user account rather than an organization, so the single-contributor concentration is not compensated by visible organizational backing.
One contributor made all 2 recent commits, leaving maintenance dependent on a single individual with no demonstrated handoff capacity.
Only 2 commits were recorded in the last 3 months, so ongoing maintenance activity is limited even though it has not stopped.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The workflow uses read-only permissions and the audit completed cleanly, but both action references are unpinned, weakening build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
3neti/hyperverge Version ^1.1 || ^2.0@beta | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-data Version ^4.17 | — | — |
propaganistas/laravel-phone Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.