Healthy and actively maintained, with a clear repository, frequent releases, tests, and two recent contributors. It is still a young 0.x package with minimal adoption and some workflow permission and security-documentation gaps.
78%
Total Score
100
100
89
50
One workflow uses pull_request_target, which warrants review because that event can expose elevated repository context. No untrusted checkouts or script-injection patterns were detected, limiting the concern.
A post-autoload-dump install-time script runs during installation, adding some supply-chain and install behavior to review, though this signal alone does not show harmful behavior.
The repository has zero stars, forks, and watchers, indicating little visible adoption or external review. This is supporting caution rather than a decisive health failure for a young package.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
Three workflows declare top-level write permissions and two declare no top-level permissions, increasing workflow privilege ambiguity. The repository's active tooling partly compensates, but least-privilege configuration is not consistently evident.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-data Version ^4.18 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
phpdocumentor/reflection Version ^6.1 || ^7.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.