Documentation is strong, and the release includes notes for its breaking change. The project is young, with all recent commits from one maintainer and workflow actions left unpinned.
65%
Total Score
75
83
50
The package is only 67 days old with two releases, both within the last 12 months. This shows recent publishing activity but provides limited long-term maintenance evidence.
One contributor made 100% of the 35 commits in the last three months. The linked project is user-owned rather than organization-owned, so there is no provided backing signal to offset this concentration.
The repository has no security policy, leaving no stated process for reporting vulnerabilities or coordinating fixes. Dependabot provides some automated dependency monitoring, but it does not replace a disclosure process.
v0.2.0 is not a stable major release, so its pre-1.0 status indicates that compatibility may still change. It is not marked as a prerelease, which partly offsets that concern.
All 11 analyzed action references are unpinned, weakening build reproducibility. Three workflows grant top-level write permissions, but the pull_request_target workflow has no untrusted checkout or script-injection finding, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.