The package includes tests, a changelog, clear usage guidance, and active releases. Workflow permissions and security scanning are sensible, though dependency pinning in CI and formal security-policy coverage could be stronger.
78%
Total Score
75
90
50
All 5 commits in the last 3 months came from one contributor, leaving maintenance dependent on a single person with no demonstrated handoff capacity.
The repository has no stars, forks, or watchers, so there is little external adoption evidence; this is supporting context rather than a health verdict, especially given the package's recent history.
No repository security policy was found. This is a modest transparency gap for a maintained package, although repository security scanning and composer-audit are present.
The workflow was fully analyzed with read-only permissions and no audit findings, but both of its action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
3neti/form-flow Version ^1.8 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
spatie/laravel-data Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.