The package includes clear usage documentation, repository tests, a changelog, and release notes for this version. Maintenance has gone quiet for three months, while workflow checks expose a high-confidence bot-condition issue and all 12 actions are unpinned.
60%
Total Score
50
100
50
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign that maintenance may be slowing after the release.
There were three open issues and one open pull request, with no issues or pull requests opened or merged in the last month; this suggests limited current engagement but not abandonment by itself.
No security policy was found, leaving vulnerability reporting and response expectations unclear for a package that handles file uploads.
All 12 action references are unpinned, and a high-confidence bot-condition finding affects the Dependabot auto-merge workflow; top-level write permissions also appear in three workflows, increasing automation hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.