It has a clear MIT license, a README, tests in the repository, and a security policy. The organization-backed project has a small dependency set and no install-time scripts.
62%
Total Score
75
100
88
83
The package is only 338 days old and has two releases, with about 188 days between them; the latest release was recent, but the release record is still limited.
The repository recorded no commits and no active maintainers in the last three months, which weakens evidence of ongoing maintenance despite the recent release.
Composer build tooling is present, but no repository security scanning tools were detected, leaving a modest security-process gap.
All three workflows use unpinned references, and the audit reported high-confidence template-injection findings in the release workflow; one file also failed analysis, so the workflow review is incomplete. These are workflow hygiene concerns rather than evidence of an unsafe package release on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
astrogoat/strata Version ^0.7.7|^0.8.0|^0.9.0|^0.10.0|^0.11.0 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.