The release is documented, licensed, tested in its repository, and backed by an organization with recent release notes. Maintenance has slowed, while workflow safeguards are weak because every action reference is unpinned and one high-confidence bot check is questionable.
64%
Total Score
75
100
94
67
The package runs a post-autoload-dump lifecycle script during installation. This is an additional install-time behavior that warrants care, though the signal does not show a harmful action.
The package has 10 releases over about 22 months, but only one release in the last 12 months; the latest release was about 3 months ago. That indicates a maintained package with a noticeably slower recent cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months, despite a release during that period. This weakens evidence of ongoing maintenance capacity.
All 12 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. Three workflows also grant top-level write access; with no untrusted checkout or script-injection findings, this is a meaningful hygiene concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.