The repository includes tests, a changelog, a clear MIT license, and dependency scanning. Its automation has broad write access, all 12 action references are unpinned, and one high-confidence workflow check is flawed.
52%
Total Score
50
100
89
50
A post-autoload-dump script runs during installation. This is common Composer behavior, but it adds install-time execution that consumers should account for.
The package and repository are owned by the same individual account, so the source identity is consistent; it does not provide organizational continuity if that maintainer stops working on it.
The latest release was in April 2023, with no releases in the last 12 months. That long release gap lowers confidence that maintenance will continue, even though the package is stable rather than prerelease.
There were no commits and no active maintainers in the last three months, reinforcing the release-history concern and indicating currently inactive development.
There were two open issues and two open pull requests, with no new or closed activity in the last month; this suggests unresolved maintenance demand rather than active support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/array-to-xml Version ^3.1 | — | — |
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.