The package includes a useful README, MIT licensing, repository tests, and release notes. Its workflows use Dependabot and Composer, but all 12 actions are unpinned and one high-confidence bot-condition finding weakens automation trust. Pin v2.0.15 only as a temporary migration measure.
12%
Total Score
0
100
57
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption and maintenance warning for the assessed release.
The package has 35 releases since December 2022, but none in the last 12 months; the latest release was about 2 years and 6 months ago. The earlier release activity does not compensate for the prolonged stoppage.
The repository recorded no commits and no active maintainers in the last 3 months. This reinforces the abandonment concern rather than showing ongoing maintenance.
The linked repository is archived, and its last push was about 2 years ago. Archived source is a strong indication that future fixes and support are unlikely.
The repository has no security policy. This reduces the transparency of vulnerability reporting, although it is secondary to the package's abandonment indicators.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.