The package is clearly documented, licensed, tested in its repository, and has matching source ownership. Its only release is brand new, with no recorded commit history or community activity yet; the missing security policy is a smaller transparency gap.
62%
Total Score
50
100
94
75
A post-autoload-dump install script is present; this is a normal Composer lifecycle hook, but it adds an install-time behavior that should be understood before adoption.
One registry account has publish access. With a user-owned project this indicates a thin publishing base, although it does not by itself show that development is inactive.
The registry namespace and repository are owned by the same individual account. That is consistent ownership, though it does not provide organizational backing.
This is the first release, published today, so there is no release track record or demonstrated maintenance cadence yet.
No commits or active maintainers were recorded during the last three months. Because the repository was created today, this mainly reflects insufficient history rather than proven abandonment, but maintenance is not yet demonstrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.