The package has a clear MIT license, strong documentation, tests, and an organization-backed repository. Its Composer install hook and workflow audit findings add operational risk, while recent repository activity is limited.
58%
Total Score
75
79
50
A post-autoload-dump script runs during installation. This is common Composer behavior, but it adds install-time execution that dependents must account for.
The package has 25 releases over about 690 days, but only 2 releases in the last 12 months, indicating a slower recent release cadence despite its historically frequent releases.
The repository recorded 0 commits and 0 active maintainers over the last 3 months. The recent release provides some counterevidence, but this still raises maintenance and abandonment concerns.
The repository name does not match the package name and its README does not mention the package, so ownership of the published package is less transparent even though the namespace and repository organization match.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these counters provide little evidence of broad external adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.