It includes tests, release notes, a clear license, and active security tooling. The release cadence is strong, but there is no published security policy.
68%
Total Score
60
100
100
63
The package runs a post-autoload-dump install-time script. This is a supply-chain and installation review point, though the signal does not show that the script is malicious or unusually broad.
Only one account has registry publish access. That is a limited publishing base, although repository activity provides evidence of an active owner rather than abandonment.
The repository is owned by an individual user rather than an organization. Combined with the single active contributor, this provides little visible organizational redundancy.
One contributor made all three commits in the last three months, giving the project a 100% top-contributor share. This concentrates maintenance and handoff risk in one person.
The repository received three commits in the last three months, with one active maintainer. Recent work is present, but the volume is modest for a package releasing frequently.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
laravel/slack-notification-channel Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.