It has an MIT license, tests, a changelog, release notes, and organization backing. Workflow automation has a high-confidence bot-condition finding, while the package remains pre-1.0.
57%
Total Score
75
75
75
The package has six releases over about nine months, but the latest release was about six months before collection. That suggests maintenance may have slowed after an initially active period.
The repository recorded zero commits and zero active maintainers in the past three months. This is concrete evidence of currently quiet maintenance, despite the recent release history.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.
This is a non-prerelease v0.0.6 release, but the pre-1.0 version still indicates an immature compatibility commitment.
All 10 analyzed action references are unpinned, and the audit found one high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this remains a workflow-hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-data Version ~4.16 | — | — |
illuminate/contracts Version ~10.0||~11.0||~12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
always-open/laravel-request-logger Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.