It has a clear README, MIT licensing, recent releases, and ongoing commits from two contributors. The install-time script and absent security policy merit extra review before adoption.
72%
Total Score
67
100
100
67
A post-autoload-dump script runs during installation, which expands install-time behavior and warrants review even though no maliciousness judgment is being made here.
The repository is owned by the same individual as the registry namespace, so there is no organizational backing to offset the concentrated contributor base.
Two contributors are active, but the top contributor made about 71% of recent commits, leaving maintenance somewhat concentrated in a user-owned project.
The repository has no security policy, which reduces transparency about how vulnerabilities should be reported and handled.
The audit covered both workflows with no reported findings or untrusted checkouts, but all five action references are unpinned and one workflow grants top-level write permission, creating avoidable workflow supply-chain and permission hygiene gaps.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.