Clear documentation, tests, release notes, and a matching repository support adoption. The small maintainer base and limited recent commit evidence leave less assurance about sustained support.
68%
Total Score
67
100
100
67
A post-autoload-dump install-time script is present. This is a modest supply-chain and installation-complexity consideration, but the signal does not show dangerous behavior by itself.
The registry and repository are owned by the same individual, so there is no ownership mismatch; the single-person backing still limits redundancy compared with an organization.
No commits or active maintainers were recorded in the last three months. Recent pull-request merges and a repository push partly offset this, but commit-level evidence of sustained maintenance is limited.
No repository security policy was found, leaving vulnerability-reporting expectations unclear for a package used in application data workflows.
The audit found a high-confidence bot-conditions issue in a pull_request_target workflow, plus all six action references are unpinned and one workflow has top-level write permissions. No untrusted checkout or script-injection sink was found, so this is a workflow-hygiene caution rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.4|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.