This release appears healthy and suitable to depend on: it is actively and frequently released, uses a stable non-prerelease version, is not deprecated, has a matching non-archived source repository, includes MIT licensing, tests, substantial package contents, and recent repository activity. The main concerns are that all recent commits come from one contributor, the package defines several install-time lifecycle scripts whose behavior is not shown here, and the repository lacks an explicit security policy and top-level GitHub Actions token permissions. These are meaningful transparency and continuity gaps, but they do not outweigh the strong release and repository evidence.
82%
Total Score
63
100
94
63
Four install/update lifecycle scripts are present: post-autoload-dump, post-create-project-cmd, post-root-package-install, and post-update-cmd. Their presence is relevant supply-chain and reproducibility risk, although this signal does not show that the scripts are unsafe.
The repository is owned by an individual user rather than an organization, so the concentrated maintainer activity represents a real single-owner continuity risk.
One contributor made all seven commits in the last 3 months, creating a genuine continuity and abandonment risk for a user-owned project.
Seven commits were made in the last 3 months, showing recent activity, but they came from only one active maintainer.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/fortify Version ^1.36 | — | — |
laravel/framework Version ^13.15 | — | — |
spatie/laravel-data Version ^4.14 | — | — |
inertiajs/inertia-laravel Version ^3.0 | — | — |
spatie/laravel-typescript-transformer Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.