Package to check that configuration key references actually exist in your config files.
68%
Total Score
63
100
100
60
One workflow uses pull_request_target for Dependabot auto-merging. No untrusted checkouts or script-injection patterns were detected, but this privileged workflow warrants caution because it operates in a sensitive pull-request context.
The package runs a post-autoload-dump Composer lifecycle script. This is an avoidable installation-time execution surface, although the signal does not show that the script is malicious or unusually complex.
Only one registry account has publish access. That is a modest resilience concern for a user-owned project, though repository activity and matching ownership provide some compensating context.
The repository recorded zero commits and zero active maintainers in the last three months. This is the clearest maintenance concern, although the recent push and release history show the project has not been abandoned for years.
There are no open issues and four open pull requests, but no issues or pull requests were newly created or merged in the last month, indicating limited current interaction.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.