Usable with caveats: the release is licensed, documented, backed by a matching organization repository, and supported by tests and release notes. It is still very young, has had no recorded commits or active maintainers in the last three months, and its repository security controls need tightening.
62%
Total Score
83
100
94
60
One workflow uses pull_request_target, which can increase CI exposure if untrusted pull-request content is handled unsafely; no untrusted checkout or script-injection pattern was detected, limiting the concern.
The package defines a post-autoload-dump install-time script; this is common in Composer packages using package tooling, but it adds install-time execution that should be reviewed before adoption.
The package is only about 100 days old and has two releases clustered within roughly 15 hours, leaving little evidence of a sustained release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a young package; the relatively recent push provides only limited compensation.
The repository has no SECURITY.md or other declared security policy, leaving vulnerability reporting and disclosure expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0||^12.0||^13.0 | — | — |
illuminate/database Version ^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.