The repository includes tests, a changelog, matching source, and a clear MIT license. Its single-maintainer base and workflow weaknesses leave less margin for reliable long-term change.
58%
Total Score
50
100
94
50
A post-autoload-dump install-time script runs during Composer installation, adding some execution risk for consumers. The signal does not show that the script is harmful, so this is a limited hygiene concern.
Only one registry account has publish access, limiting publishing redundancy. The linked repository is also owned by the same individual, so there is no organization-backed maintainer base to offset that concentration.
The package and repository are owned by the same individual account, showing consistent ownership but no organizational backing to provide additional maintenance capacity.
The package has had no registry release in over a year, with no releases in the last 12 months after four releases clustered in July 2025. This points to slowing maintenance, although the repository was still pushed more recently.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the registry's lack of releases over the same broad period, this is a meaningful maintenance risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atendwa/filakit Version ^1.0 | — | — |
atendwa/support Version ^1.0 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-activitylog Version ^4.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.