This is a generally usable and transparent Laravel development package: it has a stable 2.3.0 release, a multi-year release history, an MIT license, a matching repository with a complete source tree, repository tests, and an active organization-owned project. The main concern is maintenance momentum: the repository reports no commits or active maintainers in the last 3 months, despite a release being published recently, and the project has minimal adoption signals. Missing security scanning, an absent security policy, and unspecified workflow token permissions are additional hygiene gaps, though the analyzed workflow shows no dangerous patterns. Dependence is reasonable, but verify ongoing maintenance before making it a critical dependency.
72%
Total Score
63
100
89
70
A post-autoload-dump lifecycle script is present. This is a Composer install-time behavior that warrants awareness, but no dangerous script behavior is shown by this signal alone.
Only one registry account has publish access, which is a concentration risk; the organization-owned repository provides some compensating project backing.
The repository reports zero commits and zero active maintainers over the last 3 months, which is the clearest maintenance concern. The recent release partially offsets this, but does not establish sustained ongoing development.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is consistent with a small, quiet project, but provides little evidence of an active maintenance community.
The repository has zero stars and forks and only one watcher, indicating minimal visible adoption. Popularity is supporting evidence rather than a decisive health criterion, so this is a moderate concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0||^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.