A README, source tests, release notes, and security tooling support adoption. The single-maintainer project has little usage evidence and needs closer review of its automation.
61%
Total Score
50
100
89
63
A post-autoload-dump install script is present. This is a meaningful installation behavior to understand, but the signal alone does not show that it is unsafe or unusually complex.
Registry publishing access is held by one maintainer. That is a limited publishing fallback, although registry access alone does not establish the project's actual contributor capacity.
The source repository is owned by an individual rather than an organization, so the single registry maintainer does not have broader organizational backing to offset the thin maintainer base.
The package is young, with two releases over roughly four months and a median interval of about 53 days. This shows some release activity but provides limited evidence of long-term maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. That recent inactivity is a direct maintenance concern, though the project is still young and has not been archived.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-activitylog Version ^4.10 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.