Usable with caveats: the package has clear documentation, tests in its repository, a matching source repository, and no deprecation or dangerous workflow findings. It is brand new with no established release or commit history, and its CI workflows do not declare top-level token permissions.
62%
Total Score
50
50
89
70
Four runtime dependencies, including Laravel MCP and package tooling, form a moderate dependency surface for a Laravel integration; this is usable but adds transitive maintenance exposure.
The package runs a post-autoload-dump install-time script, which adds execution during installation and warrants review before adoption even though the signal does not identify malicious behavior.
One registry publishing account is listed, which creates a narrow publishing base; the repository is also owned by the same individual, so there is no separate organizational backing to compensate for that concentration.
The registry namespace and repository owner match, but the owner is an individual rather than an organization, so the project has limited visible institutional backing.
The package is only 0 days old with two releases, so there is not enough history to demonstrate sustained maintenance or reliable release practices.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^1.0 | — | — |
illuminate/contracts Version ^12.41.1|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.