The project has a clear README, repository tests, release notes, and an MIT license. Its workflows are fully audited but use unpinned actions, while recent repository activity is concentrated in one contributor.
63%
Total Score
50
100
94
67
The package runs post-autoload-dump and post-install-cmd scripts, adding install-time behavior that warrants extra review even though no dangerous action is shown here.
Only one registry account has publish access, which is consistent with a user-owned project but leaves limited publishing redundancy.
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor concentration is not offset by visible organizational backing.
The package is only 34 days old, with all 6 releases published on the same day, so there is little evidence of sustained maintenance over time.
All recent commits came from one contributor, concentrating maintenance responsibility and increasing continuity risk for this user-owned project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.83 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.