Use Brick/Money in your Laravel app
76%
Total Score
healthy
Healthy, with concentrated maintenance and workflow hygiene concerns.
The package defines a post-autoload-dump install-time script. This is a potentially sensitive execution point, but a single script is not by itself evidence of poor package health.
One contributor made 100% of the six commits in the last three months. Organization backing provides some handoff capacity, but the observed contributor base remains concentrated.
The repository recorded six commits in the last three months, showing recent activity. However, all six came from one active maintainer, limiting independent maintenance capacity.
The repository has no security policy. For a library handling monetary values, this is a modest transparency gap, though active releases and dependency scanning partly compensate.
All four workflows were analyzed, but all eight action references are unpinned, and one workflow has top-level write permissions. The high-confidence bot-conditions finding in the Dependabot auto-merge workflow adds a workflow hygiene concern; there is no untrusted checkout or script injection.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brick/money Version ^0.13.0||^0.14.0||^0.15.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.