The package is clearly licensed, documented, and backed by a matching organization repository with tests, releases, and security guidance. Its very short history limits maintenance evidence, and all eight workflow actions are unpinned.
78%
Total Score
75
94
67
The package runs a post-autoload-dump install-time script, which adds execution during installation and deserves review, though this alone is not evidence of an unsafe dependency.
Only two releases exist and the package is less than one day old, so long-term maintenance cannot yet be demonstrated. The recent release activity is encouraging but does not establish durability.
There are no commits or active maintainers recorded over the last three months, but the repository and release were created very recently, so this is limited history rather than established abandonment.
All four workflows were analyzed with no audit findings or untrusted triggers, but all eight action references are unpinned, leaving avoidable dependency-drift risk in CI.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
filament/filament Version ^5.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
bbs-lab/laravel-force-two-factor Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.