The package is clearly licensed, documented, and backed by a matching organization repository with tests and security scanning. Its very small release history and inactive recent commits leave maintenance uncertain, while workflow permissions and an unsafe bot check add avoidable release risk.
58%
Total Score
75
100
81
63
A post-autoload-dump script runs during installation. This is common Composer package behavior, but it adds execution during dependency installation and merits ordinary review.
Only two releases have been published, both within about three days, and no later registry releases appear during the package's roughly ten-month lifetime. This is limited evidence of sustained maintenance.
There were zero commits and zero active maintainers in the latest three months. For a package released only twice, this is a meaningful maintenance concern even though the repository is not archived.
There are no open issues and one open pull request, but no issues or pull requests were merged in the latest month. The quiet tracker offers little evidence of active maintenance.
The repository has one star, no forks, and no watchers. Popularity is only supporting evidence, but these low counts provide little external evidence of maturity or community support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0||^11.0||^12.0 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
dynamik-dev/cloak-php Version ^0.2 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.