Unfit to use: Packagist marks the package abandoned and its source repository is archived. The package has a clear license, documentation, tests, and security tooling, but those positives do not offset the lack of an active maintenance path.
18%
Total Score
57
67
Packagist marks the entire package as abandoned, with no replacement package specified. This is a severe warning that future fixes and compatibility work may not be available.
The package has eight releases since July 2022, but none in the last two and a half years; its latest release was in February 2024. That absence of recent releases reinforces the abandonment concerns.
The linked source repository is archived, so it is no longer an active maintenance venue even though it was pushed in February 2025. This creates a severe risk for future support and updates.
One of five workflows uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script-injection patterns were detected, so this is a limited workflow concern rather than a decisive health issue.
Three workflows lack top-level token permissions, and the Dependabot auto-merge workflow has write permissions. This weakens workflow hardening, though it is secondary to the package's abandonment status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^4.32 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
spatie/laravel-ray Version ^1.33 | — | — |
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.