Balanced contributors and an organization-owned repository improve confidence. The project is still young, has only two commits in three months, and lacks repository security scanning and a security policy. Its changelog, license, stable version, and matching source repository provide useful safeguards.
65%
Total Score
67
100
88
50
The package runs a post-autoload-dump install-time script. This adds execution during installation and warrants care, although the signal provides no evidence that the script is unsafe.
The package has only four releases and is about five months old, with releases concentrated near its initial publication and no release for nearly five months. That leaves limited evidence of sustained release maintenance.
Two contributors each supplied half of the recent commits, avoiding single-contributor concentration. The small contributor count still limits the depth of the maintenance base.
Only two commits were recorded in the last three months, which is sparse for an actively evolving package. Two active maintainers provide some compensation, but the recent maintenance record remains limited.
Composer build tooling is present, but no security-scanning tool was detected. This is a transparency and maintenance-process gap, not evidence of a defect in the release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/once Version * | — | — |
laravel/sanctum Version * | — | — |
laravel/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.