Clear documentation, a matching repository, a license, and repository tests support adoption. The release is still young, recent commit activity is absent, and workflow checks include risky automation hygiene that merits review.
64%
Total Score
50
86
67
The package runs a post-autoload-dump install-time script, which expands installation behavior beyond loading files and deserves review before use in sensitive builds.
The package is 277 days old with only two releases, both concentrated within about two days, so its long-term maintenance pattern is not yet established.
There were zero commits and zero active maintainers in the past three months, a meaningful sign that maintenance may be slowing despite the repository remaining active recently.
Version 0.2.0 is not a prerelease, but the 0.x major version indicates an API that may still change substantially.
All five analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target workflow has broad write permissions, although no untrusted checkout or script injection was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-data Version ^4.6 | — | — |
illuminate/contracts Version ^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.