The project is actively releasing and has a clear organization-backed repository with tests, documentation, and a license. Maintenance is concentrated in one recent contributor, and the repository lacks security policy and scanning coverage.
68%
Total Score
80
100
94
75
All two recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second recent contributor is shown to share the maintenance load.
The repository received two commits in the past three months, all from one active maintainer. Recent work exists, but the low activity and single active contributor limit maintenance resilience.
Composer build tooling is present, but no security scanning tools are configured, leaving a meaningful part of the repository's security hygiene unverified.
The repository has no security policy, so the project does not document a clear process for reporting and handling vulnerabilities.
All 15 analyzed action references are unpinned, weakening build reproducibility; two workflows grant top-level write access, though no dangerous triggers, untrusted checkouts, script injections, or audit findings were detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.