The repository includes tests, a changelog, matching package references, and Dependabot coverage. The single release is an alpha from over two years ago, with no commits in three months and a high-confidence workflow condition warning.
48%
Total Score
67
100
75
50
Only one release exists, from over two years ago, with no releases in the last 12 months. This is strong evidence of limited maintenance for a dependency.
There were no commits and no active maintainers in the last three months. Combined with the single old release, this indicates currently inactive maintenance.
All five workflows were analyzed, but all 12 action references are unpinned, three workflows grant top-level write access, and a high-confidence bot-conditions finding affects Dependabot auto-merge. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not dangerous on its own.
The repository is not archived, although its last push was in July 2024; the active repository status partly offsets abandonment concerns but does not overcome the stale release record.
The repository has no security policy. This is a transparency gap, though it is less serious than the package's inactive release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.