Clear licensing, documentation, tests, and release notes provide a solid starting point. The repository is active and correctly tied to the package, but ongoing support remains concentrated in one contributor and the workflows leave actions unpinned.
67%
Total Score
50
100
92
67
This is a five-day-old package with only one release, so there is not enough history to demonstrate sustained maintenance or compatibility over time.
One contributor holds all four recent commits, creating a low bus factor; there is no organization backing signal to offset that concentration.
Four commits in the last three months show recent activity, but all activity comes from one active maintainer, so long-term support capacity remains limited.
The repository has no security policy, which is a transparency gap for reporting and handling security issues, though it is not evidence of a vulnerability by itself.
Both workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all four referenced actions are unpinned, so workflow dependencies are less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^13.24.0 | — | — |
spatie/laravel-data Version ^4.23.0 | — | — |
inertiajs/inertia-laravel Version ^3.3.1 | — | — |
spatie/laravel-typescript-transformer Version ^2.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.