Tests, a changelog, and a clear README improve day-to-day adoption, and the repository is active rather than archived. The proprietary license, missing security policy, and unpinned workflow actions add practical concerns.
63%
Total Score
50
86
50
The manifest declares a proprietary license, so the release is licensed, but it may restrict use or redistribution compared with a permissive open-source license. No license file was detected to clarify the terms.
The package is 50 days old with only one release, so there is little evidence of release maturity or long-term maintenance. Its stable v1.0.0 status partly offsets this, but does not establish a durable track record.
All 2 commits in the last 3 months came from one contributor, giving the project a concentrated maintenance base. The linked repository is correctly matched to the package, but no second active contributor is shown.
Two commits in the last 3 months show some recent activity, which is better than a dormant project, but the low volume limits evidence of sustained maintenance.
No security policy is present in the repository. For an onboarding component handling identity and authentication boundaries, this is a transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/database Version ^12.0 || ^13.0 | — | — |
spatie/laravel-data Version ^4.17 | — | — |
propaganistas/laravel-phone Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.