Reusable polymorphic key mapping for Laravel packages
62%
Total Score
caution
Usable with caveats: no commits in the last three months and all 8 workflow actions are unpinned.
Only one registry account has publish access, which concentrates publishing responsibility, although the linked repository provides direct ownership context.
The registry namespace and repository owner differ, and the repository is owned by an individual rather than an organization; this offers limited visible institutional backing.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance warning despite the package's recent release history.
The repository uses Composer and Just for build tooling, but no security scanning tool was detected, leaving a modest hygiene gap.
The sole workflow was fully analyzed with no dangerous sinks or audit findings, but all 8 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
facade/ignition-contracts Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.