This release appears generally suitable to depend on: it is not deprecated or archived, has a matching repository with an organization owner, a clear MIT license, tests, changelog, security policy, and substantial release activity. Maintenance is recent but relatively light, with only 2 commits from 2 contributors in the last 3 months, and the package remains below a stable major version. The zero-star repository is only supporting evidence, not a decisive concern, while the install-time script and broad GitHub Actions write permissions merit review before use in a high-assurance environment.
78%
Total Score
90
100
83
70
One workflow uses pull_request_target, which can be security-sensitive, but no untrusted checkout or script-injection patterns were detected across the four analyzed workflows.
A post-autoload-dump install-time lifecycle script is present. This is an additional execution surface and warrants inspection, although the signal does not establish that the script is unsafe.
Only 2 commits occurred in the last 3 months, indicating light recent development. Both activity and contributor counts are nonzero, so this is a maintenance caution rather than a severe abandonment signal.
The repository has zero stars, forks, and watchers, which provides no external adoption evidence. Popularity is supporting evidence only, so this modestly limits confidence rather than indicating abandonment by itself.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a transparency and assurance gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-data Version ~4.16 | — | — |
illuminate/contracts Version ~10.0||~11.0||~12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
always-open/laravel-request-logger Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.