Usable with caveats: the package is licensed, well-documented, tested, actively releasing, and backed by a matching repository. The main concern is zero recorded commits or active maintainers in the last three months despite the current release, plus limited repository security tooling.
72%
Total Score
75
100
94
80
A post-autoload-dump install script is present. This is a normal Composer integration point, but it adds install-time behavior that should be understood before adoption.
Only one account has registry publish access, which creates a limited publishing-capacity concern. The user-owned repository and recent release activity provide some compensation, but not a second maintainer.
No commits and no active maintainers were recorded in the last three months, which is a meaningful maintenance concern. The recent 2.4.0 release and same-day repository push partly offset this, but the activity pattern is still thin.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and defense-in-depth gap, not evidence that the package is unsafe.
All workflows declare permissions; two use read-only permissions and two use top-level write permissions for release and label synchronization tasks. The explicit declarations are good practice, though write access increases workflow impact if compromised.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3|^8.0 | — | — |
nesbot/carbon Version ^3.10 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
grazulex/laravel-modelschema Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.