Usable with caveats: this is a well-scaffolded, clearly matched Laravel package, but it is less than three hours old and has no demonstrated maintenance history yet. Review its install script and GitHub workflow permissions before adopting it broadly.
66%
Total Score
50
100
93
60
One of five workflows uses pull_request_target for Dependabot auto-merge. No untrusted checkouts or script-injection patterns were detected, so the workflow setup presents limited but real review risk.
A post-autoload-dump install-time script is present. This is a meaningful execution point for consumers and warrants review, though the signal alone does not establish that the script is unsafe.
One registry publishing account creates a limited bus for releases, but the linked repository is owned by the same individual and the package is not organization-backed, so this remains a modest resilience concern.
The registry namespace and repository owner match, but both identify an individual rather than an organization, so the package has limited visible institutional backing.
The package is less than three hours old and has only two releases, so there is not yet enough history to demonstrate sustained maintenance or release discipline.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grantholle/scru128 Version ^1.0 | — | — |
illuminate/database Version ^11.0||^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.