Usable with caveats: the package is licensed, documented, tested, and backed by a matching repository with a recent release. However, maintenance is currently quiet, with no commits in the last three months, and repository workflow permissions and security-policy gaps add operational risk.
64%
Total Score
50
94
60
Five workflows were analyzed without untrusted checkouts or script injection, but one uses pull_request_target for automated Dependabot merging, which warrants care because that trigger runs with elevated trust.
A post-autoload-dump install-time script runs during Composer installation, adding execution surface for consumers, although this is not by itself evidence of poor maintenance.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so the project appears to rely on a single-owner backing model.
The package is about 17 months old but has only three releases, with one release in the last 12 months and a median interval of about 193 days, indicating a relatively slow release cadence.
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful sign that maintenance may be slowing despite the more recent push recorded elsewhere.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
illuminate/validation Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
giggsey/libphonenumber-for-php-lite Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.