Usable with caveats: the release is well documented, tested, licensed, and backed by a matching organization repository, but maintenance evidence is mixed. There were no commits or active maintainers in the last three months, and the project has limited security tooling and uneven workflow permissions.
68%
Total Score
63
100
89
80
Only one registry account has publish access, but the repository is organization-owned, which provides some backing and makes a short registry maintainer list less concerning.
The package is about 12 months old but has only two releases, with one release in the last 12 months and an interval of about 373 days; this leaves maintenance continuity uncertain.
The repository recorded zero commits and zero active maintainers over the last three months. This is a meaningful maintenance concern, despite the recent push and current release.
There are no open issues and two open pull requests, but no issues or pull requests were merged during the last month, so current responsiveness is not demonstrated.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap that is not offset by the otherwise complete package structure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.