Repository tests, release notes, licensing, and a matching organization-backed source provide useful transparency. Workflow references are unpinned and the repository has no security policy, adding maintenance and hygiene concerns.
65%
Total Score
67
100
88
50
The package uses a post-autoload-dump lifecycle script. This adds install-time behavior that deserves review, but the signal does not show that it is unsafe or unusually broad.
The package has 9 releases since June 2022, but none in the last 12 months; this suggests the project may be slowing, though the assessed version was released recently enough to show it is not abandoned outright.
There were no commits and no active maintainers in the last 3 months, a concrete sign that maintenance may have slowed despite the repository being recently pushed.
There are 15 open pull requests and 2 open issues, with none opened or merged in the last month; this indicates unresolved project activity rather than a cleanly active development flow.
Composer is used for builds, but no security scanning tools are configured, leaving automated supply-chain and code checks less visible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.