The single-maintainer base and absent security policy add ownership and disclosure limits. A complete README, repository tests, changelog, and MIT licensing provide useful transparency.
55%
Total Score
50
50
100
50
Eight runtime dependencies, including framework, Google API, and package-tooling components, create a broader update surface than a minimal utility package.
The package runs a post-autoload-dump install lifecycle script. This is common in Composer packages but still adds execution during installation.
Only one registry account has publish access. The repository is user-owned rather than organization-owned, so there is no provided backing signal to offset the narrow publishing base.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance even though the project has a release history.
No security policy was found in the repository, leaving reporting and disclosure expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/invade Version ^2.1 | — | — |
google/apiclient Version ^2.18 | — | — |
filament/filament Version ^3.3 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-sluggable Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.