Usable with caveats: this is a newly published package with only one release, and all recent repository work comes from one contributor. Organization backing, tests, documentation, active commits, and a clean non-deprecated repository are reassuring, but workflow permissions are not explicitly restricted.
72%
Total Score
88
100
88
88
The package is only 4 days old and has one release, so there is not yet enough release history to establish long-term maintenance or stability.
One contributor made all 7 recent commits, creating a genuine continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
Both workflows omit top-level token permissions, so their GitHub Actions token access is not explicitly constrained to read-only permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
astrogoat/strata Version ^0.7.0|^0.8.0|^0.9.0|^0.10.0|^0.11.0 | — | — |
illuminate/contracts Version ^8.37 || ^v9.9|^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.