A Laravel package that provides HTTP middleware to allow access from a centralized list of IPs
68%
Total Score
50
100
81
50
A post-autoload-dump install-time script runs during Composer operations. This adds execution during installation, though the signal does not show that the script is unsafe or unusually broad.
Only one account has registry publish access. This is a genuine continuity concern for a user-owned project, although repository activity shows that the same maintainer is currently active.
The repository is owned by an individual user rather than an organization, so the concentrated maintainer and contributor activity is not offset by visible organizational backing.
The package is 473 days old with only three releases, two in the last 12 months, and a median release interval of about 195 days. That is a slow but not abandoned cadence, especially given the release as recently as June 25, 2026.
All two recent commits came from one contributor, leaving no demonstrated backup maintainer if that person becomes unavailable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.