A single organization backs the package, and the latest release has clear notes plus repository tests. Its short release history and limited workflow hygiene leave less maintenance and publishing margin than mature dependencies.
67%
Total Score
75
100
94
50
The package has only three releases across about two years and one release in the last 12 months, indicating a modest maintenance cadence rather than broad ongoing activity.
The repository recorded zero commits and zero active maintainers in the last three months, reducing evidence of current maintenance capacity.
The repository has no security policy, leaving contributors without a documented reporting route; this is a transparency gap, though it does not by itself make the package unfit.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection sink, so this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0 || ^12.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.