Recent releases, release notes, and repository tests provide useful maintenance evidence. However, all recent commits come from one contributor, and the workflow audit found a high-confidence bot-condition issue plus all eight action references unpinned.
44%
Total Score
83
86
50
Packagist marks the entire package as abandoned, with no distinct replacement identified. This is a substantial adoption and maintenance risk even though the release itself is recent.
All 15 recent commits came from one contributor, leaving maintenance dependent on a single active developer. Organization ownership provides some handoff capacity, but no second active contributor is shown.
No repository security policy was found. This is a transparency gap, though the package's active repository and dependency scanning provide limited compensating evidence.
The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow, and all 8 action references are unpinned; two workflows also grant top-level write permissions. No untrusted checkout or script-injection sink was found, limiting this to a hygiene and workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.