The package includes a clear README, changelog, extensive repository tests, and an MIT license. Its single maintainer, absent security scanning, and fully unpinned workflow actions reduce confidence for production use.
69%
Total Score
50
100
88
83
Registry publishing is controlled by one account, which creates a thin maintainer base and increases continuity risk for a young project.
The repository is owned by an individual account rather than an organization, so the single-maintainer concern is not offset by visible organizational backing.
Four releases arrived over roughly six months with a median interval of about two weeks, showing an initially active project; the latest release is now about three months old.
There were no commits and no active maintainers in the last three months, indicating that maintenance has recently gone quiet despite the earlier release cadence.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and review gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.