Usable with caveats: the package is licensed, documented, tested in its repository, and clearly backed by a matching source project. However, it has had no registry release for about 14 months and no recorded commits in the last 3 months, so maintenance appears uncertain despite a recent repository push.
58%
Total Score
50
100
89
60
One of five workflows uses pull_request_target for Dependabot auto-merge, which carries elevated workflow risk; no untrusted checkout or script-injection patterns were detected.
A post-autoload-dump script runs during installation. This is a meaningful supply-chain consideration, though the signal does not show it performing unusual or dangerous actions.
Only one registry publishing maintainer is listed. This is consistent with the individually owned repository but still indicates limited publishing redundancy.
The registry namespace and repository owner match, but the project is maintained by an individual rather than an organization, leaving a relatively narrow ownership base.
The package released 14 versions rapidly in July 2025 but has had no release in about 14 months. That long registry silence lowers confidence in ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/queue Version ^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.