Healthy and suitable to use, with a narrow maintenance risk. The repository is actively maintained, releases are documented, and security tooling is present, but all recent commits come from one contributor and some workflows grant write permissions.
78%
Total Score
75
100
100
80
A post-autoload-dump install-time script runs during Composer installation, which deserves awareness because lifecycle code executes automatically, though this signal alone does not show unsafe behavior.
The registry namespace and repository are owned by the same individual, so the single-person maintainer concentration is not offset by organization backing.
All 51 recent commits came from one contributor, so maintenance depends heavily on a single person and has limited redundancy.
Three workflows omit top-level permissions and two declare top-level write permissions, which is weaker workflow least-privilege hygiene even though no dangerous workflow pattern was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.1 | — | — |
illuminate/support Version * | — | — |
illuminate/contracts Version * | — | — |
spatie/laravel-event-sourcing Version ^7.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.