Usable with caveats: the package is licensed, documented, tested in its repository, and not deprecated or archived. However, it has had no registry release in over two years and no commits in the last three months, so maintenance appears stalled.
58%
Total Score
0
100
83
50
There were no commits and no active maintainers in the last three months, reinforcing the release-history evidence that maintenance is currently stalled.
One workflow uses pull_request_target for Dependabot auto-merge, but no untrusted checkout or script-injection patterns were detected. The workflow pattern warrants review but is not severe on the collected evidence.
A post-autoload-dump install script runs during Composer installation. This is a supply-chain-sensitive behavior that deserves review, although the signal does not establish that it is harmful.
Only two releases were published, with the latest over two years ago and no releases in the last 12 months. This is a meaningful sign of low ongoing maintenance for a deployment utility.
The repository has only 3 stars and 1 fork. Low popularity is supporting evidence rather than a defect, but it provides little independent evidence of broad review or adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.