The package includes tests, a changelog, clear integration guidance, and Composer security checks. Workflow references are unpinned and the project has no security policy, leaving avoidable maintenance and build-hygiene gaps.
58%
Total Score
50
100
86
75
The manifest declares a proprietary license, with no detected license text or license file. This provides a legal grant but limits suitability for projects expecting an open-source dependency.
The package is only 50 days old with three releases and a median interval of about 16 days. That shows active early development but provides little evidence of long-term stability.
One contributor made all five commits in the last three months, so maintenance depends entirely on a single person.
Five commits occurred in the last three months, but all activity is attributed to one active maintainer. Recent work is present, though the maintenance base is narrow.
The repository has no security policy. That is a transparency and response-process gap, especially for a package handling disclosure-related functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 || ^13.0 | — | — |
illuminate/routing Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
spatie/laravel-data Version ^4.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.