Usable with caveats: the release is well documented, tested in its repository, licensed, and actively maintained, but it is only 37 days old with one release and all recent commits from one contributor. Review its GitHub Actions permissions before adopting it in a sensitive build environment.
72%
Total Score
75
100
94
70
One of three workflows uses pull_request_target, which can expose elevated workflow context when handling pull requests. No untrusted checkout or script injection was detected, limiting the demonstrated risk.
A post-autoload-dump install script is present. This is a real supply-chain surface, though the signal does not show a broader or unusually invasive set of lifecycle scripts.
Only one registry account has publishing access. The repository is organization-owned, which provides some continuity beyond the registry account, but the publishing base remains narrow.
This is a young package, only 37 days old, with a single release and no established release interval, so long-term maintenance reliability is not yet demonstrated.
One contributor made all 11 commits in the last three months, creating a concentrated maintenance dependency; organization backing reduces but does not remove this risk because no second active contributor is shown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/events Version ^12.0||^13.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.