adapty.io API for Laravel
68%
Total Score
63
100
83
75
The package uses a post-autoload-dump install-time script. This adds execution surface during installation and warrants review, although the signal does not show a dangerous script by itself.
The artifact has a substantial README and changelog, and the repository uses GitHub Releases, but neither the artifact nor repository contains tests. Documentation and release tooling compensate for some transparency needs, while the absence of tests remains a maintenance gap.
The repository is owned by the individual account gridwb, with no organization backing shown. This is consistent with the single-maintainer activity and leaves limited evidence of maintenance handoff capacity.
One contributor performed 100% of the three-month commit activity. Because the repository owner is an individual rather than an organization, there is no project-backing evidence to offset this concentration.
Only one commit was recorded in the last three months, from one active maintainer. Recent releases and a current push provide some compensating evidence, but the low sustained commit activity is a genuine maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.9||^8.0 | — | — |
spatie/laravel-data Version ^4.13 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.