Healthy and reasonable to adopt, with some maintenance caveats. It has a matching organization-backed repository, strong documentation and tests, and 26 stable releases in 51 days, but recorded commit activity is currently absent and the repository has no security scanning or policy.
76%
Total Score
75
100
89
80
The package defines a post-autoload-dump lifecycle script. This can be normal for framework package setup, but it adds install-time execution surface and warrants review before adoption.
The repository records zero commits and zero active maintainers over the last three months. The recent release and push activity partly offsets this, but the absence of recorded development activity is a maintenance concern.
The repository has zero stars, forks, and watchers. This provides no external adoption evidence, but popularity is supporting evidence only and the package is very new.
Composer build tooling is present, but no security scanning tools were detected. For a package defining notification contracts and including integration-related code, this is a transparency and maintenance gap.
No security policy was found in the repository. This does not make the package unusable, but it leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0 | — | — |
mateusjunges/laravel-kafka Version ^2.11 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.