The package has a clear MIT license, documentation, repository tests, and organization backing. Its release history and recent repository activity are too thin for confidence in ongoing maintenance, while workflow hygiene adds adoption risk.
45%
Total Score
50
78
33
This is the only release, published about 2 years and 10 months ago, with no releases in the last 12 months. That is strong evidence of limited maintenance activity.
There were no commits and no active maintainers in the last 3 months. Combined with a single release, this indicates a substantial risk of abandonment or inactive maintenance.
All 12 analyzed action references are unpinned, and a high-confidence audit found spoofable bot conditions in the Dependabot auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection finding, but the combined workflow hygiene still raises risk.
The package runs a post-autoload-dump install-time script. This is a real supply-chain and installation consideration, though the signal does not show that the script is unsafe.
There are no new or closed issues in the last month, and two pull requests remain open. This shows little recent project movement and leaves maintenance responsiveness uncertain.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
theaddresstech/ddd Version ^1.1 | — | — |
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.