Healthy and reasonable to adopt, with some early-project caveats. It has active recent development, a stable release, tests and CI in the repository, but the project is only 59 days old and maintenance is concentrated in one main contributor.
78%
Total Score
67
100
60
One workflow uses pull_request_target, which warrants review because that trigger can expose elevated repository context. However, the scan found no untrusted checkout or script-injection patterns.
The package uses a post-autoload-dump install lifecycle script. This adds installation-time behavior that deserves review, but it is not severe on its own and no other supplied signal indicates that the script is unsafe.
The repository is owned by an individual user rather than an organization, so the concentrated contributor activity and single registry maintainer represent the actual available maintenance base. Recent commits partly compensate for that limited backing.
Two contributors were active, but the leading contributor made 80% of recent commits. The second contributor provides some continuity, while the concentration still creates a moderate maintenance risk for a user-owned project.
The repository has no security policy. That reduces transparency about vulnerability reporting and response, though it does not by itself indicate abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-model-states Version ^2.12 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.