The project is only 92 days old and still below 1.0, but it has released seven times and remains actively developed. Its small, concentrated contributor base and workflow hygiene leave meaningful maintenance and build-integrity caveats.
68%
Total Score
88
100
89
50
A post-autoload-dump install script runs during Composer installation. This is a supply-chain and installation-behavior consideration, though the signal does not show that the script is unsafe.
Two contributors were active, but one made 87.5% of the recent commits. The organization-owned project provides some handoff capacity, partially offsetting this concentration.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation but does not by itself indicate poor health.
No repository security policy was found. This is a transparency gap for a package handling application data and permissions, though it is not evidence of an active defect.
Version 0.5.0 is not a stable major release, so APIs may still change; it is nevertheless not marked as a prerelease and recent releases contain no prerelease versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.