Its MIT license, matching repository, README, and repository tests improve transparency. The single maintainer and absent security policy leave less operational depth.
67%
Total Score
50
100
81
50
A post-autoload-dump install-time script is present. This is a modest supply-chain and installation-complexity concern, although no other provided signal indicates that the script is dangerous.
The package has only 3 releases over about 2.5 years, with a median interval of about 12 months and just 1 release in the last 12 months. This indicates sparse maintenance for a dependency, though a recent release provides some evidence of continued ownership.
The repository had 0 commits and 0 active maintainers in the last 3 months. Combined with the roughly annual release cadence, this leaves limited evidence of active ongoing maintenance.
The project uses Composer, but no security-scanning tool was detected. This is a limited hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. That reduces transparency around vulnerability reporting and response, especially for a package intended to be reused by other projects.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.