The MIT license, focused file set, repository tests, and matching source give consumers useful transparency. The small dependency set and stable version reduce integration uncertainty, though ongoing support should not be expected.
58%
Total Score
0
100
79
50
The package has had no releases in the last 12 months, and its latest release was on July 1, 2024 despite being about 2 years and 6 months old at collection time. This is meaningful evidence of stalled maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, corroborating the absence of recent registry releases and raising support risk.
The repository has 0 stars, 0 forks, and 1 watcher, providing little evidence of community adoption or a broader support base. Popularity is supporting evidence, so this lowers confidence in long-term resilience rather than deciding the verdict alone.
The linked repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented, which is a transparency gap for a package intended to be used in applications.
Both workflows were analyzed successfully with no reported audit findings or untrusted checkouts, but all 5 action references are unpinned and one workflow grants top-level write permissions. The permissions are not paired with an identified untrusted sink, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/valuestore Version ^1.3 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.