Usable with caveats: the release is clearly packaged, documented, tested in its repository, and not deprecated or archived. It is brand new with no demonstrated maintenance history, and repository workflow permissions and security tooling leave room for improvement.
68%
Total Score
50
88
90
The registry namespace and repository belong to the same individual account, so the package has consistent ownership. Individual ownership also means the maintainer base is inherently narrow.
This is the first and only release, published less than a day ago, so there is no track record yet for maintenance or reliable release cadence.
The repository has no commits from the last three months and no active maintainers in that window. Because the project was created and released less than a day ago, this is mainly an absence of history rather than evidence of abandonment, but ongoing maintenance remains unproven.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency gap rather than a severe risk, especially because other repository checks are present.
Two workflows omit top-level permissions and two request top-level write permissions. The signal does not show excessive job-level access, but narrower explicit permissions would reduce CI supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.