The repository has had no commits in the last three months, and all 10 workflow actions are unpinned. A recent v2.0.0 release, repository tests, and release notes provide useful maintenance evidence.
68%
Total Score
83
100
81
100
The package has only 4 releases over about 2 years and 11 months, with one release in the last 12 months and a median interval of about 11 months. The latest release is recent, but the slow cadence limits maintenance confidence.
There were 0 commits and 0 active maintainers in the last three months. The recent release provides some counterevidence, but the lack of ongoing repository activity is a real maintenance concern.
The repository has 1 star and 0 forks, indicating limited adoption. Popularity is supporting evidence only, so this modestly reduces maturity confidence without determining the health verdict.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of unsafe code.
All 4 workflows were analyzed successfully with no reported audit findings or untrusted-code sinks. However, all 10 action references are unpinned, leaving workflow dependencies exposed to mutable upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.