Collection of useful traits for my laravel projects.
47%
Total Score
unhealthy
Risky: nearly two years without releases or commits, with unsafe and incomplete workflow automation.
The latest release was nearly two years ago, and there were no releases in the preceding 12 months of collection. This indicates materially slowed maintenance despite the package having a stable version.
The repository recorded zero commits and zero active maintainers during the last three months, reinforcing the long release gap and increasing abandonment risk.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a package with several runtime dependencies.
The audit was incomplete because 1 of 4 workflows failed analysis; all 6 analyzed action references were unpinned, two workflows grant top-level write access, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a serious hygiene concern rather than a standalone critical risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-sluggable Version ^3.6 | — | — |
spatie/laravel-activitylog Version ^4.8 | — | — |
spatie/laravel-medialibrary Version ^11.4 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.