Healthy and reasonable to use. It has a matching, active source repository with recent commits, tests, release notes, licensing, and automated dependency scanning; the main caveats are a very small user base and some GitHub Actions permission and security-policy gaps.
82%
Total Score
90
100
94
60
One workflow uses pull_request_target, which warrants review because it can run with elevated repository context. However, no untrusted checkout or script-injection patterns were detected across the five analyzed workflows.
A post-autoload-dump install script is present. This is a meaningful install-time behavior to review, but the signal provides no evidence that it is unsafe or unusually broad.
Only one registry account has publish access, which is a narrow publishing base. The organization-owned repository and recent activity provide some compensation, but registry continuity still depends on one account.
The repository has one star and no forks or watchers. This indicates limited external adoption, but popularity is supporting evidence and does not outweigh the repository's active maintenance signals.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/scout Version ^10.0|^11.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.