Healthy and suitable to use, with a small maintenance risk. The package is actively releasing, tested in its repository, licensed, and backed by an organization, but all recent commits come from one contributor and workflow permissions are broader than ideal.
78%
Total Score
88
100
94
60
One of five workflows uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger has elevated context, but no untrusted checkout or script-injection patterns were detected.
The package runs a post-autoload-dump install-time script. This is a meaningful installation behavior to review, although the signal does not show a harmful script or unusually broad action.
One contributor made all 18 commits in the last 3 months, creating a real continuity risk; organization ownership partly compensates because maintenance can potentially be handed off.
The repository has no stars, forks, or watchers, so there is little external adoption evidence; this is only supporting evidence and does not outweigh the strong release and commit activity.
No security policy is present, leaving vulnerability-reporting expectations less transparent for users of this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.